2020-06-03T06:34:14Z DEBUG Logging to /var/log/ipareplica-install.log 2020-06-03T06:34:14Z DEBUG ipa-replica-install was invoked with arguments [] and options: {'unattended': True, 'ip_addresses': [CheckedIPAddress('172.18.0.4')], 'domain_name': 'ipa.test', 'servers': ['master1.ipa.test'], 'realm_name': 'IPA.TEST', 'host_name': None, 'principal': 'admin', 'hidden_replica': False, 'setup_adtrust': False, 'setup_ca': True, 'setup_kra': False, 'setup_dns': False, 'no_pkinit': False, 'no_ui_redirect': False, 'dirsrv_config_file': None, 'dirsrv_cert_files': None, 'http_cert_files': None, 'pkinit_cert_files': None, 'dirsrv_cert_name': None, 'http_cert_name': None, 'pkinit_cert_name': None, 'keytab': None, 'mkhomedir': False, 'force_join': False, 'ntp_servers': ['1.pool.ntp.org'], 'ntp_pool': 'pool.ntp.org', 'no_ntp': False, 'force_ntpd': False, 'ssh_trust_dns': False, 'no_ssh': False, 'no_sshd': False, 'no_dns_sshfp': False, 'skip_schema_check': False, 'pki_config_override': None, 'allow_zone_overlap': False, 'reverse_zones': None, 'no_reverse': False, 'auto_reverse': False, 'forwarders': None, 'no_forwarders': False, 'auto_forwarders': False, 'forward_policy': None, 'no_dnssec_validation': False, 'no_host_dns': False, 'add_sids': False, 'add_agents': False, 'enable_compat': False, 'netbios_name': None, 'no_msdcs': False, 'rid_base': None, 'secondary_rid_base': None, 'skip_conncheck': False, 'verbose': False, 'quiet': False, 'log_file': None} 2020-06-03T06:34:14Z DEBUG IPA version 4.8.6-alt1 2020-06-03T06:34:14Z DEBUG Searching for an interface of IP address: ::1 2020-06-03T06:34:14Z DEBUG Testing local IP address: ::1/128 (interface: lo) 2020-06-03T06:34:14Z DEBUG Starting external process 2020-06-03T06:34:14Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:34:14Z DEBUG Process finished, return code=1 2020-06-03T06:34:14Z DEBUG stdout= 2020-06-03T06:34:14Z DEBUG stderr= 2020-06-03T06:34:14Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:34:14Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:34:14Z DEBUG httpd is not configured 2020-06-03T06:34:14Z DEBUG kadmin is not configured 2020-06-03T06:34:14Z DEBUG dirsrv is not configured 2020-06-03T06:34:14Z DEBUG pki-tomcatd is not configured 2020-06-03T06:34:14Z DEBUG install is not configured 2020-06-03T06:34:14Z DEBUG krb5kdc is not configured 2020-06-03T06:34:14Z DEBUG named is not configured 2020-06-03T06:34:14Z DEBUG filestore is tracking no files 2020-06-03T06:34:14Z DEBUG Starting external process 2020-06-03T06:34:14Z DEBUG args=['/sbin/systemctl', 'is-enabled', 'ntpd.service'] 2020-06-03T06:34:14Z DEBUG Process finished, return code=1 2020-06-03T06:34:14Z DEBUG stdout= 2020-06-03T06:34:14Z DEBUG stderr=Failed to get unit file state for ntpd.service: No such file or directory 2020-06-03T06:34:14Z DEBUG Starting external process 2020-06-03T06:34:14Z DEBUG args=['/sbin/systemctl', 'is-active', 'ntpd.service'] 2020-06-03T06:34:14Z DEBUG Process finished, return code=3 2020-06-03T06:34:14Z DEBUG stdout=inactive 2020-06-03T06:34:14Z DEBUG stderr= 2020-06-03T06:34:14Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index' 2020-06-03T06:34:14Z DEBUG Configuring client side components 2020-06-03T06:34:14Z DEBUG Starting external process 2020-06-03T06:34:14Z DEBUG args=['/usr/sbin/ipa-client-install', '--unattended', '--domain', 'ipa.test', '--server', 'master1.ipa.test', '--realm', 'IPA.TEST', '--principal', 'admin', '--ip-address', '172.18.0.4', '--ntp-server', '1.pool.ntp.org', '--ntp-pool', 'pool.ntp.org'] 2020-06-03T06:34:31Z DEBUG Process finished, return code=0 2020-06-03T06:34:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:34:31Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:34:31Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-03T06:34:31Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-03T06:34:31Z DEBUG skipping plugin module ipaserver.plugins.dogtag: dogtag not selected as RA plugin 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-03T06:34:31Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-03T06:34:31Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-03T06:34:31Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-03T06:34:31Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-03T06:34:31Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-03T06:34:31Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-03T06:34:31Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-03T06:34:32Z DEBUG Check if replica1.ipa.test is a primary hostname for localhost 2020-06-03T06:34:32Z DEBUG Primary hostname for localhost: replica1.ipa.test 2020-06-03T06:34:32Z DEBUG Search DNS for replica1.ipa.test 2020-06-03T06:34:32Z DEBUG Check if replica1.ipa.test is not a CNAME 2020-06-03T06:34:32Z DEBUG Check reverse address of 172.18.0.4 2020-06-03T06:34:32Z DEBUG Found reverse name: replica1.ipa.test 2020-06-03T06:34:32Z DEBUG Search DNS for master1.ipa.test 2020-06-03T06:34:32Z DEBUG Check if master1.ipa.test is not a CNAME 2020-06-03T06:34:32Z DEBUG Check reverse address of 172.18.0.2 2020-06-03T06:34:32Z DEBUG Found reverse name: master1.ipa.test 2020-06-03T06:34:32Z DEBUG Initializing principal host/replica1.ipa.test@IPA.TEST using keytab /etc/krb5.keytab 2020-06-03T06:34:32Z DEBUG using ccache /tmp/.private/root/krbccm17ir9ma/ccache /tmp/.private/root/krbcc84dibxfp/ccache 2020-06-03T06:34:32Z DEBUG Attempt 1/1: success 2020-06-03T06:34:32Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-03T06:34:32Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-03T06:34:32Z DEBUG skipping plugin module ipaserver.plugins.dogtag: dogtag not selected as RA plugin 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-03T06:34:32Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-03T06:34:32Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-03T06:34:32Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-03T06:34:32Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-03T06:34:32Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-03T06:34:32Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-03T06:34:32Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-03T06:34:33Z DEBUG failed to find session_cookie in persistent storage for principal 'host/replica1.ipa.test@IPA.TEST' 2020-06-03T06:34:33Z DEBUG trying https://master1.ipa.test/ipa/json 2020-06-03T06:34:33Z DEBUG Created connection context.jsonclient_140690291340624 2020-06-03T06:34:33Z DEBUG [try 1]: Forwarding 'env' to json server 'https://master1.ipa.test/ipa/json' 2020-06-03T06:34:33Z DEBUG New HTTP connection (master1.ipa.test) 2020-06-03T06:34:33Z DEBUG received Set-Cookie ()'['ipa_session=MagBearerToken=7AUV%2b1xE4z7SgI9IkcgRduKwZ1kA949fmrbaP8SXxaoKIYRrKCJgg1G7gtWNpi0Ep%2bXTCxQRxlVJgoV3DgE4zdnqBRICZELWlnQndEY6kjdKdn6Be3Agp1cu7zrsfa8ZfMu5RWqmQL7R1ZwFeznkw3Y4Wv85ZRO%2fWiPnfyFL0bBetpgVh7NuftpExPXUd19cwxbWXZ48Ruk4GHTgAdI9xwIMBSDFsxv2R%2bxI59h5OFpJxTPyEa8vQo0tMx4Sf5AS;path=/ipa;httponly;secure;']' 2020-06-03T06:34:33Z DEBUG storing cookie 'ipa_session=MagBearerToken=7AUV%2b1xE4z7SgI9IkcgRduKwZ1kA949fmrbaP8SXxaoKIYRrKCJgg1G7gtWNpi0Ep%2bXTCxQRxlVJgoV3DgE4zdnqBRICZELWlnQndEY6kjdKdn6Be3Agp1cu7zrsfa8ZfMu5RWqmQL7R1ZwFeznkw3Y4Wv85ZRO%2fWiPnfyFL0bBetpgVh7NuftpExPXUd19cwxbWXZ48Ruk4GHTgAdI9xwIMBSDFsxv2R%2bxI59h5OFpJxTPyEa8vQo0tMx4Sf5AS;' for principal host/replica1.ipa.test@IPA.TEST 2020-06-03T06:34:33Z DEBUG [try 1]: Forwarding 'env' to json server 'https://master1.ipa.test/ipa/json' 2020-06-03T06:34:33Z DEBUG HTTP connection keep-alive (master1.ipa.test) 2020-06-03T06:34:33Z DEBUG received Set-Cookie ()'['ipa_session=MagBearerToken=7Y3LqoonSTlg2arQqh%2fFZdOExvedZ0mI10aerBh8SJeq3Q0ZmAbbqgn4VJawsyC0iH2vHIOQx21OjkMxmodDqR%2bigN1danre7LfopGTzUE%2f%2bGRZ4POk1q55itpxz3tXBlpit7p4Pxfnl7BVw%2f%2bnU97LSgASZob9mHCOsK3dUNBaaFOegAg36KxJaFf0TqlMlKAHQv8BA1%2btmeZ%2ftD9DFQJq6CRiAgK%2b8I%2bcJWfwWNvgAj9KbX5hCKyrP7FBZr57H;path=/ipa;httponly;secure;']' 2020-06-03T06:34:33Z DEBUG storing cookie 'ipa_session=MagBearerToken=7Y3LqoonSTlg2arQqh%2fFZdOExvedZ0mI10aerBh8SJeq3Q0ZmAbbqgn4VJawsyC0iH2vHIOQx21OjkMxmodDqR%2bigN1danre7LfopGTzUE%2f%2bGRZ4POk1q55itpxz3tXBlpit7p4Pxfnl7BVw%2f%2bnU97LSgASZob9mHCOsK3dUNBaaFOegAg36KxJaFf0TqlMlKAHQv8BA1%2btmeZ%2ftD9DFQJq6CRiAgK%2b8I%2bcJWfwWNvgAj9KbX5hCKyrP7FBZr57H;' for principal host/replica1.ipa.test@IPA.TEST 2020-06-03T06:34:33Z DEBUG Destroyed connection context.jsonclient_140690291340624 2020-06-03T06:34:33Z DEBUG Created connection context.ldap2_140690300568192 2020-06-03T06:34:33Z DEBUG flushing ldaps://master1.ipa.test from SchemaCache 2020-06-03T06:34:33Z DEBUG retrieving schema for SchemaCache url=ldaps://master1.ipa.test conn= 2020-06-03T06:34:33Z DEBUG raw: domainlevel_get(version='2.236') 2020-06-03T06:34:33Z DEBUG domainlevel_get(version='2.236') 2020-06-03T06:34:33Z DEBUG raw: hostgroup_find(None, cn='ipaservers', version='2.236', host=['replica1.ipa.test']) 2020-06-03T06:34:33Z DEBUG hostgroup_find(None, cn='ipaservers', all=False, raw=False, version='2.236', no_members=True, pkey_only=False, host=('replica1.ipa.test',)) 2020-06-03T06:34:33Z DEBUG KRB5CCNAME set to None 2020-06-03T06:34:33Z DEBUG Failed to find default ccache: Major (851968): Unspecified GSS failure. Minor code may provide more information, Minor (2529639053): No Kerberos credentials available (default cache: FILE:/tmp/krb5cc_0) 2020-06-03T06:34:33Z DEBUG Initializing principal admin@IPA.TEST using password 2020-06-03T06:34:33Z DEBUG Starting external process 2020-06-03T06:34:33Z DEBUG args=['/usr/bin/kinit', 'admin@IPA.TEST', '-c', '/tmp/.private/root/tmp_9gsl7o0'] 2020-06-03T06:34:33Z DEBUG Process finished, return code=0 2020-06-03T06:34:33Z DEBUG stdout=Password for admin@IPA.TEST: 2020-06-03T06:34:33Z DEBUG stderr= 2020-06-03T06:34:33Z DEBUG Destroyed connection context.ldap2_140690300568192 2020-06-03T06:34:33Z DEBUG Created connection context.ldap2_140690300568192 2020-06-03T06:34:33Z DEBUG raw: hostgroup_show('ipaservers', rights=True, all=True, version='2.236') 2020-06-03T06:34:33Z DEBUG hostgroup_show('ipaservers', rights=True, all=True, raw=False, version='2.236', no_members=False) 2020-06-03T06:34:33Z DEBUG flushing ldaps://master1.ipa.test from SchemaCache 2020-06-03T06:34:33Z DEBUG retrieving schema for SchemaCache url=ldaps://master1.ipa.test conn= 2020-06-03T06:34:33Z DEBUG Destroyed connection context.ldap2_140690300568192 2020-06-03T06:34:33Z DEBUG Created connection context.ldap2_140690300568192 2020-06-03T06:34:33Z DEBUG flushing ldaps://master1.ipa.test from SchemaCache 2020-06-03T06:34:33Z DEBUG retrieving schema for SchemaCache url=ldaps://master1.ipa.test conn= 2020-06-03T06:34:33Z WARNING Lookup failed: Preferred host replica1.ipa.test does not provide DNS. 2020-06-03T06:34:33Z DEBUG Check forward/reverse DNS resolution 2020-06-03T06:34:33Z DEBUG Search DNS server master1.ipa.test (['172.18.0.2', '172.18.0.2', '172.18.0.2']) for master1.ipa.test 2020-06-03T06:34:33Z DEBUG Check reverse address 172.18.0.2 (master1.ipa.test) 2020-06-03T06:34:33Z DEBUG Address 172.18.0.2 resolves to: master1.ipa.test.. 2020-06-03T06:34:33Z DEBUG Search DNS server master1.ipa.test (['172.18.0.2', '172.18.0.2', '172.18.0.2']) for replica1.ipa.test 2020-06-03T06:34:33Z DEBUG Check reverse address 172.18.0.4 (replica1.ipa.test) 2020-06-03T06:34:33Z DEBUG Address 172.18.0.4 resolves to: replica1.ipa.test.. 2020-06-03T06:34:33Z DEBUG Name replica1.ipa.test resolved to {UnsafeIPAddress('172.18.0.4')} 2020-06-03T06:34:33Z DEBUG Searching for an interface of IP address: 172.18.0.4 2020-06-03T06:34:33Z DEBUG Testing local IP address: 127.0.0.1/255.0.0.0 (interface: lo) 2020-06-03T06:34:33Z DEBUG Testing local IP address: 172.18.0.4/255.255.0.0 (interface: eth0) 2020-06-03T06:34:33Z DEBUG Destroyed connection context.ldap2_140690300568192 2020-06-03T06:34:33Z DEBUG Starting external process 2020-06-03T06:34:33Z DEBUG args=['/usr/sbin/ipa-replica-conncheck', '--master', 'master1.ipa.test', '--auto-master-check', '--realm', 'IPA.TEST', '--hostname', 'replica1.ipa.test', '--principal', 'admin', '--password', XXXXXXXX, '--ca-cert-file', '/etc/ipa/ca.crt'] 2020-06-03T06:34:38Z DEBUG Process finished, return code=0 2020-06-03T06:34:38Z DEBUG stdout= 2020-06-03T06:34:38Z DEBUG stderr=Check connection from replica to remote master 'master1.ipa.test': Directory Service: Unsecure port (389): OK Directory Service: Secure port (636): OK Kerberos KDC: TCP (88): OK Kerberos Kpasswd: TCP (464): OK HTTP Server: Unsecure port (80): OK HTTP Server: Secure port (443): OK The following list of ports use UDP protocol and would need to be checked manually: Kerberos KDC: UDP (88): SKIPPED Kerberos Kpasswd: UDP (464): SKIPPED Connection from replica to master is OK. Start listening on required ports for remote master check Get credentials to log in to remote master Check RPC connection to remote master Execute check on remote master Check connection from master to remote replica 'replica1.ipa.test': Directory Service: Unsecure port (389): OK Directory Service: Secure port (636): OK Kerberos KDC: TCP (88): OK Kerberos KDC: UDP (88): OK Kerberos Kpasswd: TCP (464): OK Kerberos Kpasswd: UDP (464): OK HTTP Server: Unsecure port (80): OK HTTP Server: Secure port (443): OK Connection from master to replica is OK. 2020-06-03T06:34:38Z DEBUG Starting external process 2020-06-03T06:34:38Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:34:38Z DEBUG Process finished, return code=1 2020-06-03T06:34:38Z DEBUG stdout= 2020-06-03T06:34:38Z DEBUG stderr= 2020-06-03T06:34:38Z DEBUG Created PKCS#11 module config '/etc/pkcs11/modules/softhsm2.module'. 2020-06-03T06:34:38Z DEBUG Created connection context.ldap2_140690300568192 2020-06-03T06:34:38Z DEBUG raw: hostgroup_add_member('ipaservers', version='2.236', host=['replica1.ipa.test']) 2020-06-03T06:34:38Z DEBUG hostgroup_add_member('ipaservers', all=False, raw=False, version='2.236', no_members=False, host=('replica1.ipa.test',)) 2020-06-03T06:34:38Z DEBUG add_entry_to_group: dn=fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test group_dn=cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test member_attr=member 2020-06-03T06:34:38Z DEBUG flushing ldaps://master1.ipa.test from SchemaCache 2020-06-03T06:34:38Z DEBUG retrieving schema for SchemaCache url=ldaps://master1.ipa.test conn= 2020-06-03T06:34:38Z DEBUG Destroyed connection context.ldap2_140690300568192 2020-06-03T06:34:38Z DEBUG Starting external process 2020-06-03T06:34:38Z DEBUG args=['/sbin/systemctl', 'is-active', 'dbus.service'] 2020-06-03T06:34:38Z DEBUG Process finished, return code=0 2020-06-03T06:34:38Z DEBUG stdout=active 2020-06-03T06:34:38Z DEBUG stderr= 2020-06-03T06:34:38Z DEBUG Starting external process 2020-06-03T06:34:38Z DEBUG args=['/sbin/systemctl', 'restart', 'certmonger.service'] 2020-06-03T06:34:38Z DEBUG Process finished, return code=0 2020-06-03T06:34:38Z DEBUG stdout= 2020-06-03T06:34:38Z DEBUG stderr= 2020-06-03T06:34:38Z DEBUG Starting external process 2020-06-03T06:34:38Z DEBUG args=['/sbin/systemctl', 'is-active', 'certmonger.service'] 2020-06-03T06:34:38Z DEBUG Process finished, return code=0 2020-06-03T06:34:38Z DEBUG stdout=active 2020-06-03T06:34:38Z DEBUG stderr= 2020-06-03T06:34:38Z DEBUG Restart of certmonger.service complete 2020-06-03T06:34:38Z DEBUG Starting external process 2020-06-03T06:34:38Z DEBUG args=['/sbin/systemctl', 'enable', 'certmonger.service'] 2020-06-03T06:34:39Z DEBUG Process finished, return code=0 2020-06-03T06:34:39Z DEBUG stdout= 2020-06-03T06:34:39Z DEBUG stderr=Created symlink /etc/systemd/system/multi-user.target.wants/certmonger.service → /lib/systemd/system/certmonger.service. 2020-06-03T06:34:39Z DEBUG Created connection context.ldap2_140690300568192 2020-06-03T06:34:39Z DEBUG flushing ldaps://master1.ipa.test from SchemaCache 2020-06-03T06:34:39Z DEBUG retrieving schema for SchemaCache url=ldaps://master1.ipa.test conn= 2020-06-03T06:34:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:34:39Z DEBUG Configuring directory server (dirsrv). Estimated time: 30 seconds 2020-06-03T06:34:39Z DEBUG [1/41]: creating directory server instance 2020-06-03T06:34:39Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:34:39Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:34:39Z DEBUG Running setup with verbose 2020-06-03T06:34:39Z DEBUG START: Starting installation... 2020-06-03T06:34:39Z DEBUG READY: Preparing installation for IPA-TEST... 2020-06-03T06:34:39Z DEBUG PASSED: using config settings 999999999 2020-06-03T06:34:39Z DEBUG PASSED: user / group checking 2020-06-03T06:34:39Z DEBUG PASSED: prefix checking 2020-06-03T06:34:39Z DEBUG list instance not found in /etc/dirsrv/slapd-IPA-TEST/dse.ldif: IPA-TEST 2020-06-03T06:34:39Z DEBUG PASSED: instance checking 2020-06-03T06:34:39Z DEBUG INFO: temp root password set to W9zU3B8eX3jFuXDbwmyDzQQyZt1O0CazcionecSN4e.1dRFzgNe5gGs958wr4gMdg 2020-06-03T06:34:39Z DEBUG PASSED: root user checking 2020-06-03T06:34:39Z DEBUG PASSED: network avaliability checking 2020-06-03T06:34:39Z DEBUG READY: Beginning installation for IPA-TEST... 2020-06-03T06:34:39Z DEBUG ACTION: Creating dse.ldif 2020-06-03T06:34:39Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:34:39Z DEBUG ACTION: creating /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:39Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-IPA-TEST/db 2020-06-03T06:34:39Z DEBUG ACTION: creating /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:34:39Z DEBUG ACTION: creating /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:39Z DEBUG ACTION: creating /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:39Z DEBUG ACTION: creating /var/run/dirsrv 2020-06-03T06:34:39Z DEBUG CMD: systemctl enable dirsrv@IPA-TEST ; STDOUT: ; STDERR: Created symlink /etc/systemd/system/multi-user.target.wants/dirsrv@IPA-TEST.service → /lib/systemd/system/dirsrv@.service. 2020-06-03T06:34:39Z DEBUG ACTION: Creating certificate database is /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:39Z DEBUG Allocate with None 2020-06-03T06:34:39Z DEBUG Allocate with replica1.ipa.test:389 2020-06-03T06:34:39Z DEBUG Allocate with replica1.ipa.test:389 2020-06-03T06:34:39Z DEBUG nss cmd: /usr/bin/certutil -N -d /etc/dirsrv/slapd-IPA-TEST -f /etc/dirsrv/slapd-IPA-TEST/pwdfile.txt 2020-06-03T06:34:39Z DEBUG nss output: 2020-06-03T06:34:39Z DEBUG nss cmd: /usr/bin/certutil -N -d /etc/dirsrv/ssca/ -f /etc/dirsrv/ssca//pwdfile.txt 2020-06-03T06:34:39Z DEBUG nss output: 2020-06-03T06:34:40Z DEBUG nss cmd: /usr/bin/certutil -S -n Self-Signed-CA -s CN=ssca.389ds.example.com,O=testing,L=389ds,ST=Queensland,C=AU -x -g 4096 -t CT,, -v 24 -2 --keyUsage certSigning -d /etc/dirsrv/ssca/ -z /etc/dirsrv/ssca//noise.txt -f /etc/dirsrv/ssca//pwdfile.txt 2020-06-03T06:34:42Z DEBUG nss output: Is this a CA certificate [y/N]? Enter the path length constraint, enter to skip [<0 for unlimited path]: > Is this a critical extension [y/N]? 2020-06-03T06:34:42Z DEBUG nss cmd: /usr/bin/certutil -L -n Self-Signed-CA -d /etc/dirsrv/ssca/ -a 2020-06-03T06:34:42Z DEBUG nss cmd: /usr/bin/c_rehash /etc/dirsrv/ssca/ 2020-06-03T06:34:43Z DEBUG nss cmd: /usr/bin/certutil -R --keyUsage digitalSignature,nonRepudiation,keyEncipherment,dataEncipherment --nsCertType sslClient,sslServer --extKeyUsage clientAuth,serverAuth -s CN=replica1.ipa.test,givenName=0aa878e8-be29-49c3-bccf-86f71944443a,O=testing,L=389ds,ST=Queensland,C=AU -8 replica1.ipa.test -g 4096 -d /etc/dirsrv/slapd-IPA-TEST -z /etc/dirsrv/slapd-IPA-TEST/noise.txt -f /etc/dirsrv/slapd-IPA-TEST/pwdfile.txt -a -o /etc/dirsrv/slapd-IPA-TEST/Server-Cert.csr 2020-06-03T06:34:45Z DEBUG nss cmd: /usr/bin/certutil -C -d /etc/dirsrv/ssca/ -f /etc/dirsrv/ssca//pwdfile.txt -v 24 -a -i /etc/dirsrv/slapd-IPA-TEST/Server-Cert.csr -o /etc/dirsrv/slapd-IPA-TEST/Server-Cert.crt -c Self-Signed-CA 2020-06-03T06:34:46Z DEBUG nss cmd: /usr/bin/c_rehash /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:46Z DEBUG nss cmd: /usr/bin/certutil -A -n Self-Signed-CA -t CT,, -a -i /etc/dirsrv/slapd-IPA-TEST/ca.crt -d /etc/dirsrv/slapd-IPA-TEST -f /etc/dirsrv/slapd-IPA-TEST/pwdfile.txt 2020-06-03T06:34:46Z DEBUG nss cmd: /usr/bin/certutil -A -n Server-Cert -t ,, -a -i /etc/dirsrv/slapd-IPA-TEST/Server-Cert.crt -d /etc/dirsrv/slapd-IPA-TEST -f /etc/dirsrv/slapd-IPA-TEST/pwdfile.txt 2020-06-03T06:34:46Z DEBUG nss cmd: /usr/bin/certutil -V -d /etc/dirsrv/slapd-IPA-TEST -n Server-Cert -u YCV 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping port relabel 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /var/lib/dirsrv/slapd-IPA-TEST/db 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /var/run/dirsrv 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping relabel path /tmp 2020-06-03T06:34:46Z DEBUG selinux is disabled, skipping port relabel 2020-06-03T06:34:46Z DEBUG systemd status -> True 2020-06-03T06:34:46Z DEBUG systemd status -> True 2020-06-03T06:34:48Z DEBUG open(): Connecting to uri ldap://replica1.ipa.test:389/ 2020-06-03T06:34:48Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:48Z DEBUG Using external ca certificate /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:48Z DEBUG Using external ca certificate /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:48Z DEBUG Using certificate policy 1 2020-06-03T06:34:48Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 1 2020-06-03T06:34:48Z DEBUG open(): bound as cn=Directory Manager 2020-06-03T06:34:48Z DEBUG open(): Connecting to uri ldap://replica1.ipa.test:389/ 2020-06-03T06:34:48Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:48Z DEBUG Using external ca certificate /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:48Z DEBUG Using external ca certificate /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:48Z DEBUG Using certificate policy 1 2020-06-03T06:34:48Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 1 2020-06-03T06:34:48Z DEBUG open(): bound as cn=Directory Manager 2020-06-03T06:34:48Z DEBUG cn=config set REPLACE: ('nsslapd-secureport', '636') 2020-06-03T06:34:48Z DEBUG cn=config set REPLACE: ('nsslapd-security', 'on') 2020-06-03T06:34:48Z DEBUG Checking "None" under cn=ldbm database,cn=plugins,cn=config : {'cn': 'userRoot', 'nsslapd-suffix': 'dc=ipa,dc=test'} 2020-06-03T06:34:48Z DEBUG Using first property cn: userRoot as rdn 2020-06-03T06:34:48Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=dc=ipa,dc=test)(nsslapd-backend=dc=ipa,dc=test))) 2020-06-03T06:34:49Z DEBUG _gen_selector filter = (&(&(objectclass=nsMappingTree))(|(cn=userRoot)(nsslapd-backend=userRoot))) 2020-06-03T06:34:49Z DEBUG Validated dn cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:34:49Z DEBUG Creating cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:34:49Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:34:49Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance']} 2020-06-03T06:34:49Z DEBUG updating dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:34:49Z DEBUG updated dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config with {'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=ipa,dc=test']} 2020-06-03T06:34:49Z DEBUG Created entry cn=userRoot,cn=ldbm database,cn=plugins,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsBackendInstance'], 'cn': [b'userRoot'], 'nsslapd-suffix': [b'dc=ipa,dc=test']} 2020-06-03T06:34:49Z DEBUG Checking "None" under cn=mapping tree,cn=config : {'cn': [b'dc=ipa,dc=test'], 'nsslapd-state': 'backend', 'nsslapd-backend': [b'userRoot']} 2020-06-03T06:34:49Z DEBUG Using first property cn: dc\=ipa\,dc\=test as rdn 2020-06-03T06:34:49Z DEBUG Validated dn cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:34:49Z DEBUG Creating cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:34:49Z DEBUG updating dn: cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:34:49Z DEBUG updated dn: cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config with {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree']} 2020-06-03T06:34:49Z DEBUG updating dn: cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:34:49Z DEBUG updated dn: cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config with {'cn': [b'dc=ipa,dc=test', b'dc\\=ipa\\,dc\\=test'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2020-06-03T06:34:49Z DEBUG Created entry cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config : {'objectclass': [b'top', b'extensibleObject', b'nsMappingTree'], 'cn': [b'dc=ipa,dc=test', b'dc\\=ipa\\,dc\\=test'], 'nsslapd-state': [b'backend'], 'nsslapd-backend': [b'userRoot']} 2020-06-03T06:34:49Z DEBUG cn=config set REPLACE: ('nsslapd-ldapifilepath', '/var/run/slapd-IPA-TEST.socket') 2020-06-03T06:34:49Z DEBUG cn=config set REPLACE: ('nsslapd-ldapilisten', 'on') 2020-06-03T06:34:49Z DEBUG cn=config set REPLACE: ('nsslapd-ldapiautobind', 'on') 2020-06-03T06:34:49Z DEBUG cn=config set REPLACE: ('nsslapd-ldapimaprootdn', 'cn=Directory Manager') 2020-06-03T06:34:49Z DEBUG Adding sasl maps for suffix dc=ipa,dc=test 2020-06-03T06:34:49Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'rfc 2829 u syntax', 'nsSaslMapRegexString': '^u:\\(.*\\)', 'nsSaslMapBaseDNTemplate': 'dc=ipa,dc=test', 'nsSaslMapFilterTemplate': '(uid=\\1)'} 2020-06-03T06:34:49Z DEBUG Using first property cn: rfc 2829 u syntax as rdn 2020-06-03T06:34:49Z DEBUG Validated dn cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-06-03T06:34:49Z DEBUG Creating cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-06-03T06:34:49Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-06-03T06:34:49Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2020-06-03T06:34:49Z DEBUG updating dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config 2020-06-03T06:34:49Z DEBUG updated dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config with {'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=ipa,dc=test'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2020-06-03T06:34:49Z DEBUG Created entry cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'rfc 2829 u syntax'], 'nsSaslMapRegexString': [b'^u:\\(.*\\)'], 'nsSaslMapBaseDNTemplate': [b'dc=ipa,dc=test'], 'nsSaslMapFilterTemplate': [b'(uid=\\1)']} 2020-06-03T06:34:49Z DEBUG Checking "None" under cn=mapping,cn=sasl,cn=config : {'cn': 'uid mapping', 'nsSaslMapRegexString': '^[^:@]+$', 'nsSaslMapBaseDNTemplate': 'dc=ipa,dc=test', 'nsSaslMapFilterTemplate': '(uid=&)'} 2020-06-03T06:34:49Z DEBUG Using first property cn: uid mapping as rdn 2020-06-03T06:34:49Z DEBUG Validated dn cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-06-03T06:34:49Z DEBUG Creating cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-06-03T06:34:49Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-06-03T06:34:49Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'objectclass': [b'top', b'nsSaslMapping']} 2020-06-03T06:34:49Z DEBUG updating dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config 2020-06-03T06:34:49Z DEBUG updated dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config with {'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=ipa,dc=test'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2020-06-03T06:34:49Z DEBUG Created entry cn=uid mapping,cn=mapping,cn=sasl,cn=config : {'objectclass': [b'top', b'nsSaslMapping'], 'cn': [b'uid mapping'], 'nsSaslMapRegexString': [b'^[^:@]+$'], 'nsSaslMapBaseDNTemplate': [b'dc=ipa,dc=test'], 'nsSaslMapFilterTemplate': [b'(uid=&)']} 2020-06-03T06:34:49Z DEBUG cn=config set REPLACE: ('nsslapd-rootpw', '********') 2020-06-03T06:34:49Z DEBUG systemd status -> True 2020-06-03T06:34:49Z DEBUG systemd status -> True 2020-06-03T06:34:53Z DEBUG systemd status -> True 2020-06-03T06:34:53Z DEBUG systemd status -> True 2020-06-03T06:34:55Z DEBUG FINISH: Completed installation for IPA-TEST 2020-06-03T06:34:55Z DEBUG Allocate local instance with ldapi://%2fvar%2frun%2fslapd-IPA-TEST.socket 2020-06-03T06:34:55Z DEBUG open(): Connecting to uri ldapi://%2fvar%2frun%2fslapd-IPA-TEST.socket 2020-06-03T06:34:55Z DEBUG Using dirsrv ca certificate /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:55Z DEBUG Using external ca certificate /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:55Z DEBUG Using external ca certificate /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:34:55Z DEBUG Using certificate policy 1 2020-06-03T06:34:55Z DEBUG ldap.OPT_X_TLS_REQUIRE_CERT = 1 2020-06-03T06:34:55Z DEBUG open(): bound as cn=Directory Manager 2020-06-03T06:34:55Z DEBUG Checking "None" under None : {'dc': 'ipa', 'info': 'IPA V2.0'} 2020-06-03T06:34:55Z DEBUG Validated dn dc=ipa,dc=test 2020-06-03T06:34:55Z DEBUG Creating dc=ipa,dc=test 2020-06-03T06:34:55Z DEBUG updating dn: dc=ipa,dc=test 2020-06-03T06:34:55Z DEBUG updated dn: dc=ipa,dc=test with {'objectclass': [b'top', b'domain', b'pilotObject']} 2020-06-03T06:34:55Z DEBUG updating dn: dc=ipa,dc=test 2020-06-03T06:34:55Z DEBUG updated dn: dc=ipa,dc=test with {'dc': [b'ipa'], 'info': [b'IPA V2.0']} 2020-06-03T06:34:55Z DEBUG Created entry dc=ipa,dc=test : {'objectclass': [b'top', b'domain', b'pilotObject'], 'dc': [b'ipa'], 'info': [b'IPA V2.0']} 2020-06-03T06:34:55Z DEBUG completed creating DS instance 2020-06-03T06:34:55Z DEBUG step duration: dirsrv __create_instance 16.30 sec 2020-06-03T06:34:55Z DEBUG [2/41]: configure autobind for root 2020-06-03T06:34:55Z DEBUG Starting external process 2020-06-03T06:34:55Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/root-autobind.ldif', '-H', 'ldapi://%2fvar%2frun%2fslapd-IPA-TEST.socket', '-x', '-D', 'cn=Directory Manager', '-y', '/tmp/.private/root/tmprvf29aiv'] 2020-06-03T06:34:55Z DEBUG Process finished, return code=0 2020-06-03T06:34:55Z DEBUG stdout=add objectClass: extensibleObject top add cn: root-autobind add uidNumber: 0 add gidNumber: 0 adding new entry "cn=root-autobind,cn=config" modify complete replace nsslapd-ldapiautobind: on modifying entry "cn=config" modify complete replace nsslapd-ldapimaptoentries: on modifying entry "cn=config" modify complete 2020-06-03T06:34:55Z DEBUG stderr=ldap_initialize( ldapi://%2Fvar%2Frun%2Fslapd-IPA-TEST.socket/??base ) 2020-06-03T06:34:55Z DEBUG step duration: dirsrv __root_autobind 0.29 sec 2020-06-03T06:34:55Z DEBUG [3/41]: stopping directory server 2020-06-03T06:34:55Z DEBUG Starting external process 2020-06-03T06:34:55Z DEBUG args=['/sbin/systemctl', 'stop', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:34:57Z DEBUG Process finished, return code=0 2020-06-03T06:34:57Z DEBUG stdout= 2020-06-03T06:34:57Z DEBUG stderr= 2020-06-03T06:34:57Z DEBUG Stop of dirsrv@IPA-TEST.service complete 2020-06-03T06:34:57Z DEBUG step duration: dirsrv __stop_instance 2.08 sec 2020-06-03T06:34:57Z DEBUG [4/41]: updating configuration in dse.ldif 2020-06-03T06:34:58Z DEBUG Starting external process 2020-06-03T06:34:58Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:34:58Z DEBUG Process finished, return code=1 2020-06-03T06:34:58Z DEBUG stdout= 2020-06-03T06:34:58Z DEBUG stderr= 2020-06-03T06:34:58Z DEBUG step duration: dirsrv __update_dse_ldif 0.03 sec 2020-06-03T06:34:58Z DEBUG [5/41]: starting directory server 2020-06-03T06:34:58Z DEBUG Starting external process 2020-06-03T06:34:58Z DEBUG args=['/sbin/systemctl', 'start', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout= 2020-06-03T06:35:02Z DEBUG stderr= 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/sbin/systemctl', 'is-active', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=active 2020-06-03T06:35:02Z DEBUG stderr= 2020-06-03T06:35:02Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2020-06-03T06:35:02Z DEBUG waiting for port: 389 2020-06-03T06:35:02Z DEBUG SUCCESS: port: 389 2020-06-03T06:35:02Z DEBUG Start of dirsrv@IPA-TEST.service complete 2020-06-03T06:35:02Z DEBUG Created connection context.ldap2_140690310172784 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __start_instance 4.28 sec 2020-06-03T06:35:02Z DEBUG [6/41]: adding default schema 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __add_default_schemas 0.00 sec 2020-06-03T06:35:02Z DEBUG [7/41]: enabling memberof plugin 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/memberof-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=replace nsslapd-pluginenabled: on add memberofgroupattr: memberUser add memberofgroupattr: memberHost modifying entry "cn=MemberOf Plugin,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __add_memberof_module 0.02 sec 2020-06-03T06:35:02Z DEBUG [8/41]: enabling winsync plugin 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-winsync-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa-winsync add nsslapd-pluginpath: libipa_winsync add nsslapd-plugininitfunc: ipa_winsync_plugin_init add nsslapd-pluginDescription: Allows IPA to work with the DS windows sync feature add nsslapd-pluginid: ipa-winsync add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-plugin-depends-on-type: database add ipaWinSyncRealmFilter: (objectclass=krbRealmContainer) add ipaWinSyncRealmAttr: cn add ipaWinSyncNewEntryFilter: (cn=ipaConfig) add ipaWinSyncNewUserOCAttr: ipauserobjectclasses add ipaWinSyncUserFlatten: true add ipaWinsyncHomeDirAttr: ipaHomesRootDir add ipaWinsyncLoginShellAttr: ipaDefaultLoginShell add ipaWinSyncDefaultGroupAttr: ipaDefaultPrimaryGroup add ipaWinSyncDefaultGroupFilter: (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) add ipaWinSyncAcctDisable: both add ipaWinSyncForceSync: true add ipaWinSyncUserAttr: uidNumber -1 gidNumber -1 adding new entry "cn=ipa-winsync,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __add_winsync_module 0.02 sec 2020-06-03T06:35:02Z DEBUG [9/41]: configure password logging 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/pw-logging-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=replace nsslapd-unhashed-pw-switch: nolog modifying entry "cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __password_logging 0.02 sec 2020-06-03T06:35:02Z DEBUG [10/41]: configuring replication version plugin 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/version-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Version Replication add nsslapd-pluginpath: libipa_repl_version add nsslapd-plugininitfunc: repl_version_plugin_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: off add nsslapd-pluginid: ipa_repl_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Replication version plugin add nsslapd-plugin-depends-on-type: database add nsslapd-plugin-depends-on-named: Multimaster Replication Plugin adding new entry "cn=IPA Version Replication,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __config_version_module 0.02 sec 2020-06-03T06:35:02Z DEBUG [11/41]: enabling IPA enrollment plugin 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmp7944dhpw', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_enrollment_extop add nsslapd-pluginpath: libipa_enrollment_extop add nsslapd-plugininitfunc: ipaenrollment_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_enrollment_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Enroll hosts into the IPA domain add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=ipa,dc=test adding new entry "cn=ipa_enrollment_extop,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __add_enrollment_module 0.02 sec 2020-06-03T06:35:02Z DEBUG [12/41]: configuring uniqueness plugin 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmp48olpcff', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: krbPrincipalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbPrincipalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=ipa,dc=test add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test add uniqueness-across-all-subtrees: on adding new entry "cn=krbPrincipalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: krbCanonicalName uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: krbCanonicalName add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=ipa,dc=test add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test add uniqueness-across-all-subtrees: on adding new entry "cn=krbCanonicalName uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: netgroup uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=ng,cn=alt,dc=ipa,dc=test add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values adding new entry "cn=netgroup uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: ipaUniqueID uniqueness add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: ipaUniqueID add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project add nsslapd-pluginDescription: Enforce unique attribute values add uniqueness-subtrees: dc=ipa,dc=test add uniqueness-exclude-subtrees: cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test add uniqueness-across-all-subtrees: on adding new entry "cn=ipaUniqueID uniqueness,cn=plugins,cn=config" modify complete add objectClass: top nsSlapdPlugin extensibleObject add cn: sudorule name uniqueness add nsslapd-pluginDescription: Enforce unique attribute values add nsslapd-pluginPath: libattr-unique-plugin add nsslapd-pluginInitfunc: NSUniqueAttr_Init add nsslapd-pluginType: preoperation add nsslapd-pluginEnabled: on add uniqueness-attribute-name: cn add uniqueness-subtrees: cn=sudorules,cn=sudo,dc=ipa,dc=test add nsslapd-plugin-depends-on-type: database add nsslapd-pluginId: NSUniqueAttr add nsslapd-pluginVersion: 1.1.0 add nsslapd-pluginVendor: Fedora Project adding new entry "cn=sudorule name uniqueness,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __set_unique_attrs 0.04 sec 2020-06-03T06:35:02Z DEBUG [13/41]: configuring uuid plugin 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/uuid-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA UUID add nsslapd-pluginpath: libipa_uuid add nsslapd-plugininitfunc: ipauuid_init add nsslapd-plugintype: preoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipauuid_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA UUID plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA UUID,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpme2csi0d', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=add objectclass: top extensibleObject add cn: IPA Unique IDs add ipaUuidAttr: ipaUniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (|(objectclass=ipaObject)(objectclass=ipaAssociation)) add ipaUuidScope: dc=ipa,dc=test add ipaUuidEnforce: TRUE adding new entry "cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: IPK11 Unique IDs add ipaUuidAttr: ipk11UniqueID add ipaUuidMagicRegen: autogenerate add ipaUuidFilter: (objectclass=ipk11Object) add ipaUuidScope: dc=ipa,dc=test add ipaUuidEnforce: FALSE adding new entry "cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __config_uuid_module 0.30 sec 2020-06-03T06:35:02Z DEBUG [14/41]: configuring modrdn plugin 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/modrdn-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA MODRDN add nsslapd-pluginpath: libipa_modrdn add nsslapd-plugininitfunc: ipamodrdn_init add nsslapd-plugintype: betxnpostoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipamodrdn_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA MODRDN plugin add nsslapd-plugin-depends-on-type: database add nsslapd-pluginPrecedence: 60 adding new entry "cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpk5obpfs3', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=add objectclass: top extensibleObject add cn: Kerberos Principal Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbPrincipalName add ipaModRDNsuffix: @IPA.TEST add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=ipa,dc=test adding new entry "cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete add objectclass: top extensibleObject add cn: Kerberos Canonical Name add ipaModRDNsourceAttr: uid add ipaModRDNtargetAttr: krbCanonicalName add ipaModRDNsuffix: @IPA.TEST add ipaModRDNfilter: (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) add ipaModRDNscope: dc=ipa,dc=test adding new entry "cn=Kerberos Canonical Name,cn=IPA MODRDN,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __config_modrdn_module 0.04 sec 2020-06-03T06:35:02Z DEBUG [15/41]: configuring DNS plugin 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/ipa-dns-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:02Z DEBUG Process finished, return code=0 2020-06-03T06:35:02Z DEBUG stdout=add objectclass: top nsslapdPlugin extensibleObject add cn: IPA DNS add nsslapd-plugindescription: IPA DNS support plugin add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_dns add nsslapd-plugininitfunc: ipadns_init add nsslapd-pluginpath: libipa_dns.so add nsslapd-plugintype: preoperation add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-pluginversion: 1.0 add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA DNS,cn=plugins,cn=config" modify complete 2020-06-03T06:35:02Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:02Z DEBUG step duration: dirsrv __config_dns_module 0.02 sec 2020-06-03T06:35:02Z DEBUG [16/41]: enabling entryUSN plugin 2020-06-03T06:35:02Z DEBUG Starting external process 2020-06-03T06:35:02Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/entryusn.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:03Z DEBUG Process finished, return code=0 2020-06-03T06:35:03Z DEBUG stdout=replace nsslapd-entryusn-global: on modifying entry "cn=config" modify complete replace nsslapd-entryusn-import-initval: next modifying entry "cn=config" modify complete replace nsslapd-pluginenabled: on modifying entry "cn=USN,cn=plugins,cn=config" modify complete 2020-06-03T06:35:03Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:03Z DEBUG step duration: dirsrv __enable_entryusn 0.30 sec 2020-06-03T06:35:03Z DEBUG [17/41]: configuring lockout plugin 2020-06-03T06:35:03Z DEBUG Starting external process 2020-06-03T06:35:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/lockout-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:03Z DEBUG Process finished, return code=0 2020-06-03T06:35:03Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA Lockout add nsslapd-pluginpath: libipa_lockout add nsslapd-plugininitfunc: ipalockout_init add nsslapd-plugintype: object add nsslapd-pluginenabled: on add nsslapd-pluginid: ipalockout_version add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA Lockout plugin add nsslapd-plugin-depends-on-type: database adding new entry "cn=IPA Lockout,cn=plugins,cn=config" modify complete 2020-06-03T06:35:03Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:03Z DEBUG step duration: dirsrv __config_lockout_module 0.02 sec 2020-06-03T06:35:03Z DEBUG [18/41]: configuring topology plugin 2020-06-03T06:35:03Z DEBUG Starting external process 2020-06-03T06:35:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmp2ydkq8tn', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:03Z DEBUG Process finished, return code=0 2020-06-03T06:35:03Z DEBUG stdout=add objectClass: top nsSlapdPlugin extensibleObject add cn: IPA Topology Configuration add nsslapd-pluginPath: libtopology add nsslapd-pluginInitfunc: ipa_topo_init add nsslapd-pluginType: object add nsslapd-pluginEnabled: on add nsslapd-topo-plugin-shared-config-base: cn=ipa,cn=etc,dc=ipa,dc=test add nsslapd-topo-plugin-shared-replica-root: dc=ipa,dc=test o=ipaca add nsslapd-topo-plugin-shared-binddngroup: cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test add nsslapd-topo-plugin-startup-delay: 20 add nsslapd-pluginId: none add nsslapd-plugin-depends-on-named: ldbm database Multimaster Replication Plugin add nsslapd-pluginVersion: 1.0 add nsslapd-pluginVendor: none add nsslapd-pluginDescription: none adding new entry "cn=IPA Topology Configuration,cn=plugins,cn=config" modify complete 2020-06-03T06:35:03Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:03Z DEBUG step duration: dirsrv __config_topology_module 0.02 sec 2020-06-03T06:35:03Z DEBUG [19/41]: creating indices 2020-06-03T06:35:03Z DEBUG Starting external process 2020-06-03T06:35:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/indices.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:03Z DEBUG Process finished, return code=0 2020-06-03T06:35:03Z DEBUG stdout=add objectClass: top nsIndex add cn: krbPrincipalName add nsSystemIndex: false add nsIndexType: eq sub add nsMatchingRule: caseIgnoreIA5Match caseExactIA5Match adding new entry "cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: ou add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=ou,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: carLicense add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=carLicense,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: title add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=title,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: manager add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: secretary add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: displayname add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=displayname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add nsIndexType: sub modifying entry "cn=uid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: uidnumber add nsSystemIndex: false add nsIndexType: eq add nsMatchingRule: integerOrderingMatch adding new entry "cn=uidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add objectClass: top nsIndex add cn: gidnumber add nsSystemIndex: false add nsIndexType: eq add nsMatchingRule: integerOrderingMatch adding new entry "cn=gidnumber,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete replace nsIndexType: eq pres modifying entry "cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete replace nsIndexType: eq pres modifying entry "cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add ObjectClass: top nsIndex add cn: fqdn add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add ObjectClass: top nsIndex add cn: macAddress add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberHost add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberUser add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: sourcehost add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberservice add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: managedby add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberallowcmd add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberdenycmd add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipasudorunas add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipasudorunasgroup add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: automountkey add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: automountMapName add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaConfigString add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaEnabledFlag add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaKrbAuthzData add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipakrbprincipalalias add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipauniqueid add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaMemberCa add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaMemberCertProfile add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres sub adding new entry "cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: userCertificate add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipalocation add ObjectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: krbCanonicalName add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: serverhostname add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq sub adding new entry "cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: description add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: l add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsOsVersion add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsHardwarePlatform add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: nsHostLocation add objectClass: top nsindex add nssystemindex: false add nsindextype: eq sub adding new entry "cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipServicePort add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: accessRuleType add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: hostCategory add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: idnsName add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: ipaCertmapData add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: altSecurityIdentities add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq adding new entry "cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add cn: memberManager add objectClass: top nsIndex add nsSystemIndex: false add nsIndexType: eq pres adding new entry "cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete 2020-06-03T06:35:03Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:03Z DEBUG step duration: dirsrv __create_indices 0.57 sec 2020-06-03T06:35:03Z DEBUG [20/41]: enabling referential integrity plugin 2020-06-03T06:35:03Z DEBUG Starting external process 2020-06-03T06:35:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/referint-conf.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:03Z DEBUG Process finished, return code=0 2020-06-03T06:35:03Z DEBUG stdout=replace nsslapd-pluginenabled: on modifying entry "cn=referential integrity postoperation,cn=plugins,cn=config" modify complete 2020-06-03T06:35:03Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:03Z DEBUG step duration: dirsrv __add_referint_module 0.02 sec 2020-06-03T06:35:03Z DEBUG [21/41]: configuring certmap.conf 2020-06-03T06:35:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:35:03Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:35:03Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:35:03Z DEBUG step duration: dirsrv __certmap_conf 0.00 sec 2020-06-03T06:35:03Z DEBUG [22/41]: configure new location for managed entries 2020-06-03T06:35:03Z DEBUG Starting external process 2020-06-03T06:35:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmp9im7a84j', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:03Z DEBUG Process finished, return code=0 2020-06-03T06:35:03Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test modifying entry "cn=Managed Entries,cn=plugins,cn=config" modify complete 2020-06-03T06:35:03Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:03Z DEBUG step duration: dirsrv __repoint_managed_entries 0.02 sec 2020-06-03T06:35:03Z DEBUG [23/41]: configure dirsrv ccache and keytab 2020-06-03T06:35:03Z DEBUG Starting external process 2020-06-03T06:35:03Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:03Z DEBUG Process finished, return code=1 2020-06-03T06:35:03Z DEBUG stdout= 2020-06-03T06:35:03Z DEBUG stderr= 2020-06-03T06:35:03Z DEBUG Starting external process 2020-06-03T06:35:03Z DEBUG args=['/sbin/systemctl', '--system', 'daemon-reload'] 2020-06-03T06:35:03Z DEBUG Process finished, return code=0 2020-06-03T06:35:03Z DEBUG stdout= 2020-06-03T06:35:03Z DEBUG stderr= 2020-06-03T06:35:03Z DEBUG step duration: dirsrv configure_systemd_ipa_env 0.13 sec 2020-06-03T06:35:03Z DEBUG [24/41]: enabling SASL mapping fallback 2020-06-03T06:35:03Z DEBUG Starting external process 2020-06-03T06:35:03Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpmga7r445', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:04Z DEBUG Process finished, return code=0 2020-06-03T06:35:04Z DEBUG stdout=replace nsslapd-sasl-mapping-fallback: on modifying entry "cn=config" modify complete 2020-06-03T06:35:04Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:04Z DEBUG step duration: dirsrv __enable_sasl_mapping_fallback 0.28 sec 2020-06-03T06:35:04Z DEBUG [25/41]: restarting directory server 2020-06-03T06:35:04Z DEBUG Destroyed connection context.ldap2_140690310172784 2020-06-03T06:35:04Z DEBUG Starting external process 2020-06-03T06:35:04Z DEBUG args=['/sbin/systemctl', '--system', 'daemon-reload'] 2020-06-03T06:35:04Z DEBUG Process finished, return code=0 2020-06-03T06:35:04Z DEBUG stdout= 2020-06-03T06:35:04Z DEBUG stderr= 2020-06-03T06:35:04Z DEBUG Starting external process 2020-06-03T06:35:04Z DEBUG args=['/sbin/systemctl', 'restart', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:11Z DEBUG Process finished, return code=0 2020-06-03T06:35:11Z DEBUG stdout= 2020-06-03T06:35:11Z DEBUG stderr= 2020-06-03T06:35:11Z DEBUG Starting external process 2020-06-03T06:35:11Z DEBUG args=['/sbin/systemctl', 'is-active', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:11Z DEBUG Process finished, return code=0 2020-06-03T06:35:11Z DEBUG stdout=active 2020-06-03T06:35:11Z DEBUG stderr= 2020-06-03T06:35:11Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2020-06-03T06:35:11Z DEBUG waiting for port: 389 2020-06-03T06:35:11Z DEBUG SUCCESS: port: 389 2020-06-03T06:35:11Z DEBUG Restart of dirsrv@IPA-TEST.service complete 2020-06-03T06:35:11Z DEBUG Starting external process 2020-06-03T06:35:11Z DEBUG args=['/sbin/systemctl', 'is-active', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:11Z DEBUG Process finished, return code=0 2020-06-03T06:35:11Z DEBUG stdout=active 2020-06-03T06:35:11Z DEBUG stderr= 2020-06-03T06:35:11Z DEBUG Created connection context.ldap2_140690310172784 2020-06-03T06:35:11Z DEBUG step duration: dirsrv __restart_instance 7.01 sec 2020-06-03T06:35:11Z DEBUG [26/41]: creating DS keytab 2020-06-03T06:35:11Z DEBUG raw: service_add('ldap/replica1.ipa.test@IPA.TEST', force=True, version='2.236') 2020-06-03T06:35:11Z DEBUG service_add(ipapython.kerberos.Principal('ldap/replica1.ipa.test@IPA.TEST'), force=True, skip_host_check=False, all=False, raw=False, version='2.236', no_members=False) 2020-06-03T06:35:11Z DEBUG raw: host_show('replica1.ipa.test', version='2.236') 2020-06-03T06:35:11Z DEBUG host_show('replica1.ipa.test', rights=False, all=False, raw=False, version='2.236', no_members=False) 2020-06-03T06:35:11Z DEBUG Backing up system configuration file '/etc/dirsrv/ds.keytab' 2020-06-03T06:35:11Z DEBUG -> Not backing up - '/etc/dirsrv/ds.keytab' doesn't exist 2020-06-03T06:35:11Z DEBUG Starting external process 2020-06-03T06:35:11Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/etc/dirsrv/ds.keytab', '-p', 'ldap/replica1.ipa.test@IPA.TEST', '-H', 'ldaps://master1.ipa.test'] 2020-06-03T06:35:11Z DEBUG Process finished, return code=0 2020-06-03T06:35:11Z DEBUG stdout= 2020-06-03T06:35:11Z DEBUG stderr=Keytab successfully retrieved and stored in: /etc/dirsrv/ds.keytab 2020-06-03T06:35:11Z DEBUG step duration: dirsrv request_service_keytab 0.05 sec 2020-06-03T06:35:11Z DEBUG [27/41]: ignore time skew for initial replication 2020-06-03T06:35:11Z DEBUG Starting external process 2020-06-03T06:35:11Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmp0k5pe1s4', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:11Z DEBUG Process finished, return code=0 2020-06-03T06:35:11Z DEBUG stdout=replace nsslapd-ignore-time-skew: on modifying entry "cn=config" modify complete 2020-06-03T06:35:11Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:11Z DEBUG step duration: dirsrv __replica_ignore_initial_time_skew 0.03 sec 2020-06-03T06:35:11Z DEBUG [28/41]: setting up initial replication 2020-06-03T06:35:11Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:35:11Z DEBUG Destroyed connection context.ldap2_140690310172784 2020-06-03T06:35:11Z DEBUG Starting external process 2020-06-03T06:35:11Z DEBUG args=['/sbin/systemctl', '--system', 'daemon-reload'] 2020-06-03T06:35:11Z DEBUG Process finished, return code=0 2020-06-03T06:35:11Z DEBUG stdout= 2020-06-03T06:35:11Z DEBUG stderr= 2020-06-03T06:35:11Z DEBUG Starting external process 2020-06-03T06:35:11Z DEBUG args=['/sbin/systemctl', 'restart', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:16Z DEBUG Process finished, return code=0 2020-06-03T06:35:16Z DEBUG stdout= 2020-06-03T06:35:16Z DEBUG stderr= 2020-06-03T06:35:16Z DEBUG Restart of dirsrv@IPA-TEST.service complete 2020-06-03T06:35:16Z DEBUG Created connection context.ldap2_140690310172784 2020-06-03T06:35:16Z DEBUG Fetching nsDS5ReplicaId from master [attempt 1/5] 2020-06-03T06:35:16Z DEBUG retrieving schema for SchemaCache url=ldap://master1.ipa.test:389 conn= 2020-06-03T06:35:16Z DEBUG Successfully updated nsDS5ReplicaId. 2020-06-03T06:35:16Z DEBUG Add or update replica config cn=replica,cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:35:16Z DEBUG Added replica config cn=replica,cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:35:16Z DEBUG Fetching nsDS5ReplicaId from master [attempt 1/5] 2020-06-03T06:35:16Z DEBUG Successfully updated nsDS5ReplicaId. 2020-06-03T06:35:16Z DEBUG Add or update replica config cn=replica,cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:35:17Z DEBUG Added replica config cn=replica,cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:35:17Z DEBUG Waiting up to 300 seconds for replication (ldap://master1.ipa.test:389) cn=meToreplica1.ipa.test,cn=replica,cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config (objectclass=*) 2020-06-03T06:35:17Z DEBUG Entry found [LDAPEntry(ipapython.dn.DN('cn=meToreplica1.ipa.test,cn=replica,cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config'), {'objectClass': [b'nsds5replicationagreement', b'top'], 'cn': [b'meToreplica1.ipa.test'], 'nsDS5ReplicaHost': [b'replica1.ipa.test'], 'nsDS5ReplicaPort': [b'389'], 'nsds5replicaTimeout': [b'120'], 'nsDS5ReplicaRoot': [b'dc=ipa,dc=test'], 'description': [b'me to replica1.ipa.test'], 'nsDS5ReplicatedAttributeList': [b'(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'], 'nsDS5ReplicaTransportInfo': [b'LDAP'], 'nsDS5ReplicaBindMethod': [b'SASL/GSSAPI'], 'nsds5ReplicaStripAttrs': [b'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'], 'nsDS5ReplicatedAttributeListTotal': [b'(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'], 'nsds5replicareapactive': [b'0'], 'nsds5replicaLastUpdateStart': [b'19700101000000Z'], 'nsds5replicaLastUpdateEnd': [b'19700101000000Z'], 'nsds5replicaChangesSentSinceStartup': [b''], 'nsds5replicaLastUpdateStatus': [b'Error (0) No replication sessions started since server startup'], 'nsds5replicaLastUpdateStatusJSON': [b'{"state": "green", "ldap_rc": "0", "ldap_rc_text": "success", "repl_rc": "0", "repl_rc_text": "replica acquired", "date": "2020-06-03T06:35:17Z", "message": "Error (0) No replication sessions started since server startup"}'], 'nsds5replicaUpdateInProgress': [b'FALSE'], 'nsds5replicaLastInitStart': [b'19700101000000Z'], 'nsds5replicaLastInitEnd': [b'19700101000000Z']})] 2020-06-03T06:35:17Z DEBUG Waiting up to 300 seconds for replication (ldapi://%2Frun%2Fslapd-IPA-TEST.socket) cn=meTomaster1.ipa.test,cn=replica,cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config (objectclass=*) 2020-06-03T06:35:17Z DEBUG Entry found [LDAPEntry(ipapython.dn.DN('cn=meTomaster1.ipa.test,cn=replica,cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config'), {'objectClass': [b'nsds5replicationagreement', b'top'], 'cn': [b'meTomaster1.ipa.test'], 'nsDS5ReplicaHost': [b'master1.ipa.test'], 'nsDS5ReplicaPort': [b'389'], 'nsds5replicaTimeout': [b'120'], 'nsDS5ReplicaRoot': [b'dc=ipa,dc=test'], 'description': [b'me to master1.ipa.test'], 'nsDS5ReplicatedAttributeList': [b'(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'], 'nsDS5ReplicaTransportInfo': [b'LDAP'], 'nsDS5ReplicaBindMethod': [b'SASL/GSSAPI'], 'nsds5ReplicaStripAttrs': [b'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'], 'nsDS5ReplicatedAttributeListTotal': [b'(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'], 'nsds5replicareapactive': [b'0'], 'nsds5replicaLastUpdateStart': [b'19700101000000Z'], 'nsds5replicaLastUpdateEnd': [b'19700101000000Z'], 'nsds5replicaChangesSentSinceStartup': [b''], 'nsds5replicaLastUpdateStatus': [b'Error (0) No replication sessions started since server startup'], 'nsds5replicaLastUpdateStatusJSON': [b'{"state": "green", "ldap_rc": "0", "ldap_rc_text": "success", "repl_rc": "0", "repl_rc_text": "replica acquired", "date": "2020-06-03T06:35:17Z", "message": "Error (0) No replication sessions started since server startup"}'], 'nsds5replicaUpdateInProgress': [b'FALSE'], 'nsds5replicaLastInitStart': [b'19700101000000Z'], 'nsds5replicaLastInitEnd': [b'19700101000000Z']})] 2020-06-03T06:35:22Z DEBUG step duration: dirsrv __setup_replica 11.69 sec 2020-06-03T06:35:22Z DEBUG [29/41]: prevent time skew after initial replication 2020-06-03T06:35:22Z DEBUG Starting external process 2020-06-03T06:35:22Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpm_29ujvq', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:22Z DEBUG Process finished, return code=0 2020-06-03T06:35:22Z DEBUG stdout=replace nsslapd-ignore-time-skew: off modifying entry "cn=config" modify complete 2020-06-03T06:35:22Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:22Z DEBUG step duration: dirsrv replica_manage_time_skew 0.03 sec 2020-06-03T06:35:22Z DEBUG [30/41]: adding sasl mappings to the directory 2020-06-03T06:35:22Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:35:22Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:35:23Z DEBUG step duration: dirsrv __configure_sasl_mappings 0.25 sec 2020-06-03T06:35:23Z DEBUG [31/41]: updating schema 2020-06-03T06:35:23Z DEBUG Starting external process 2020-06-03T06:35:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/usr/share/ipa/schema-update.ldif', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:23Z DEBUG Process finished, return code=0 2020-06-03T06:35:23Z DEBUG stdout=add objectClasses: ( 2.16.840.1.113730.3.2.41 NAME 'nsslapdPlugin' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsslapd-pluginPath $ nsslapd-pluginInitFunc $ nsslapd-pluginType $ nsslapd-pluginId $ nsslapd-pluginVersion $ nsslapd-pluginVendor $ nsslapd-pluginDescription $ nsslapd-pluginEnabled ) MAY ( nsslapd-pluginConfigArea $ nsslapd-plugin-depends-on-type ) X-ORIGIN 'Netscape Directory Server' ) ( 2.16.840.1.113730.3.2.317 NAME 'nsSaslMapping' DESC 'Netscape defined objectclass' SUP top MUST ( cn $ nsSaslMapRegexString $ nsSaslMapBaseDNTemplate $ nsSaslMapFilterTemplate ) MAY ( nsSaslMapPriority ) X-ORIGIN 'Netscape Directory Server' ) modifying entry "cn=schema" modify complete 2020-06-03T06:35:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:23Z DEBUG step duration: dirsrv __update_schema 0.46 sec 2020-06-03T06:35:23Z DEBUG [32/41]: setting Auto Member configuration 2020-06-03T06:35:23Z DEBUG Starting external process 2020-06-03T06:35:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpi7lpiduu', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:23Z DEBUG Process finished, return code=0 2020-06-03T06:35:23Z DEBUG stdout=add nsslapd-pluginConfigArea: cn=automember,cn=etc,dc=ipa,dc=test modifying entry "cn=Auto Membership Plugin,cn=plugins,cn=config" modify complete 2020-06-03T06:35:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:23Z DEBUG step duration: dirsrv __add_replica_automember_config 0.02 sec 2020-06-03T06:35:23Z DEBUG [33/41]: enabling S4U2Proxy delegation 2020-06-03T06:35:23Z DEBUG step duration: dirsrv __setup_s4u2proxy 0.01 sec 2020-06-03T06:35:23Z DEBUG [34/41]: initializing group membership 2020-06-03T06:35:23Z DEBUG step duration: dirsrv init_memberof 0.00 sec 2020-06-03T06:35:23Z DEBUG [35/41]: adding master entry 2020-06-03T06:35:23Z DEBUG Starting external process 2020-06-03T06:35:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpdo33hg33', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:23Z DEBUG Process finished, return code=0 2020-06-03T06:35:23Z DEBUG stdout=add objectclass: top nsContainer ipaReplTopoManagedServer ipaConfigObject ipaSupportedDomainLevelConfig add cn: replica1.ipa.test add ipaReplTopoManagedSuffix: dc=ipa,dc=test add ipaMinDomainLevel: 1 add ipaMaxDomainLevel: 1 adding new entry "cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test" modify complete 2020-06-03T06:35:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:23Z DEBUG step duration: dirsrv __add_master_entry 0.02 sec 2020-06-03T06:35:23Z DEBUG [36/41]: initializing domain level 2020-06-03T06:35:23Z DEBUG step duration: dirsrv __set_domain_level 0.00 sec 2020-06-03T06:35:23Z DEBUG [37/41]: configuring Posix uid/gid generation 2020-06-03T06:35:23Z DEBUG Starting external process 2020-06-03T06:35:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpo24bjwfe', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:23Z DEBUG Process finished, return code=0 2020-06-03T06:35:23Z DEBUG stdout=add objectclass: top extensibleObject add cn: Posix IDs add dnaType: uidNumber gidNumber add dnaNextValue: 1101 add dnaMaxValue: 1100 add dnaMagicRegen: -1 add dnaFilter: (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) add dnaScope: dc=ipa,dc=test add dnaThreshold: 500 add dnaSharedCfgDN: cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test add dnaExcludeScope: cn=provisioning,dc=ipa,dc=test adding new entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete replace nsslapd-pluginEnabled: on modifying entry "cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete 2020-06-03T06:35:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:23Z DEBUG step duration: dirsrv __config_uidgid_gen 0.08 sec 2020-06-03T06:35:23Z DEBUG [38/41]: adding replication acis 2020-06-03T06:35:23Z DEBUG Starting external process 2020-06-03T06:35:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpv70_1p_v', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:23Z DEBUG Process finished, return code=0 2020-06-03T06:35:23Z DEBUG stdout=add aci: (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) modifying entry "cn=mapping tree,cn=config" modify complete add aci: (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) modifying entry "cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config" modify complete add aci: (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) modifying entry "cn=userRoot,cn=ldbm database,cn=plugins,cn=config" modify complete add aci: (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) modifying entry "cn=tasks,cn=config" modify complete 2020-06-03T06:35:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:23Z DEBUG step duration: dirsrv __add_replication_acis 0.08 sec 2020-06-03T06:35:23Z DEBUG [39/41]: activating sidgen plugin 2020-06-03T06:35:23Z DEBUG Starting external process 2020-06-03T06:35:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpb_dd5fmt', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:23Z DEBUG Process finished, return code=0 2020-06-03T06:35:23Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: IPA SIDGEN add nsslapd-pluginpath: libipa_sidgen add nsslapd-plugininitfunc: ipa_sidgen_init add nsslapd-plugintype: postoperation add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_sidgen_postop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: Red Hat, Inc. add nsslapd-plugindescription: IPA SIDGEN post operation add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=ipa,dc=test adding new entry "cn=IPA SIDGEN,cn=plugins,cn=config" modify complete 2020-06-03T06:35:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:23Z DEBUG step duration: dirsrv _add_sidgen_plugin 0.02 sec 2020-06-03T06:35:23Z DEBUG [40/41]: activating extdom plugin 2020-06-03T06:35:23Z DEBUG Starting external process 2020-06-03T06:35:23Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmpvw4f72an', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:23Z DEBUG Process finished, return code=0 2020-06-03T06:35:23Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_extdom_extop add nsslapd-pluginpath: libipa_extdom_extop add nsslapd-plugininitfunc: ipa_extdom_init add nsslapd-plugintype: extendedop add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_extdom_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support resolving IDs in trusted domains to names and back add nsslapd-plugin-depends-on-type: database add nsslapd-basedn: dc=ipa,dc=test adding new entry "cn=ipa_extdom_extop,cn=plugins,cn=config" modify complete 2020-06-03T06:35:23Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:23Z DEBUG step duration: dirsrv _add_extdom_plugin 0.02 sec 2020-06-03T06:35:23Z DEBUG [41/41]: configuring directory to start on boot 2020-06-03T06:35:23Z DEBUG Starting external process 2020-06-03T06:35:23Z DEBUG args=['/sbin/systemctl', 'is-enabled', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:23Z DEBUG Process finished, return code=0 2020-06-03T06:35:23Z DEBUG stdout=enabled 2020-06-03T06:35:23Z DEBUG stderr= 2020-06-03T06:35:23Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:23Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:23Z DEBUG Starting external process 2020-06-03T06:35:23Z DEBUG args=['/sbin/systemctl', 'disable', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=0 2020-06-03T06:35:24Z DEBUG stdout= 2020-06-03T06:35:24Z DEBUG stderr=Removed /etc/systemd/system/multi-user.target.wants/dirsrv@IPA-TEST.service. Removed /etc/systemd/system/dirsrv.target.wants/dirsrv@IPA-TEST.service. 2020-06-03T06:35:24Z DEBUG step duration: dirsrv __enable 0.18 sec 2020-06-03T06:35:24Z DEBUG Done configuring directory server (dirsrv). 2020-06-03T06:35:24Z DEBUG service duration: dirsrv 44.81 sec 2020-06-03T06:35:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG raw: dnszone_show('4.0.18.172.in-addr.arpa.', version='2.236') 2020-06-03T06:35:24Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.236') 2020-06-03T06:35:24Z DEBUG raw: dnszone_show('0.18.172.in-addr.arpa.', version='2.236') 2020-06-03T06:35:24Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.236') 2020-06-03T06:35:24Z DEBUG raw: dnszone_show('ipa.test', version='2.236') 2020-06-03T06:35:24Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.236') 2020-06-03T06:35:24Z DEBUG raw: dnsrecord_add('ipa.test', 'replica1', arecord='172.18.0.4', version='2.236') 2020-06-03T06:35:24Z DEBUG dnsrecord_add(, , arecord=('172.18.0.4',), a_extra_create_reverse=False, aaaa_extra_create_reverse=False, force=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:35:24Z INFO Replica DNS records could not be added on master: Insufficient access: Insufficient 'add' privilege to add the entry 'idnsname=replica1,idnsname=ipa.test.,cn=dns,dc=ipa,dc=test'. 2020-06-03T06:35:24Z DEBUG Destroyed connection context.ldap2_140690300568192 2020-06-03T06:35:24Z DEBUG Backing up system configuration file '/etc/ipa/default.conf' 2020-06-03T06:35:24Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:24Z DEBUG Writing configuration file /etc/ipa/default.conf 2020-06-03T06:35:24Z DEBUG [global] basedn = dc=ipa,dc=test host = replica1.ipa.test realm = IPA.TEST domain = ipa.test xmlrpc_uri = https://replica1.ipa.test/ipa/xml ldap_uri = ldapi://%2Frun%2Fslapd-IPA-TEST.socket mode = production enable_ra = True ra_plugin = dogtag dogtag_version = 10 2020-06-03T06:35:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Persistent keyring CCACHE is not enabled 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'is-active', 'krb5kdc.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=3 2020-06-03T06:35:24Z DEBUG stdout=inactive 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'stop', 'krb5kdc.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=0 2020-06-03T06:35:24Z DEBUG stdout= 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Stop of krb5kdc.service complete 2020-06-03T06:35:24Z DEBUG Configuring Kerberos KDC (krb5kdc) 2020-06-03T06:35:24Z DEBUG [1/5]: configuring KDC 2020-06-03T06:35:24Z DEBUG Backing up system configuration file '/var/lib/kerberos/krb5kdc/kdc.conf' 2020-06-03T06:35:24Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:24Z DEBUG Backing up system configuration file '/etc/krb5.conf' 2020-06-03T06:35:24Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:24Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa-server' 2020-06-03T06:35:24Z DEBUG -> Not backing up - '/etc/krb5.conf.d/freeipa-server' doesn't exist 2020-06-03T06:35:24Z DEBUG Backing up system configuration file '/etc/krb5.conf.d/freeipa' 2020-06-03T06:35:24Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:24Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb5.ini' 2020-06-03T06:35:24Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb5.ini' doesn't exist 2020-06-03T06:35:24Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krb.con' 2020-06-03T06:35:24Z DEBUG -> Not backing up - '/usr/share/ipa/html/krb.con' doesn't exist 2020-06-03T06:35:24Z DEBUG Backing up system configuration file '/usr/share/ipa/html/krbrealm.con' 2020-06-03T06:35:24Z DEBUG -> Not backing up - '/usr/share/ipa/html/krbrealm.con' doesn't exist 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/usr/bin/klist', '-V'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=0 2020-06-03T06:35:24Z DEBUG stdout=Kerberos 5 version 1.17.1 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Backing up system configuration file '/etc/sysconfig/krb5kdc' 2020-06-03T06:35:24Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=1 2020-06-03T06:35:24Z DEBUG stdout= 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG step duration: krb5kdc __configure_instance 0.03 sec 2020-06-03T06:35:24Z DEBUG [2/5]: adding the password extension to the directory 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/usr/bin/ldapmodify', '-v', '-f', '/tmp/.private/root/tmp4p16j6xm', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=0 2020-06-03T06:35:24Z DEBUG stdout=add objectclass: top nsSlapdPlugin extensibleObject add cn: ipa_pwd_extop add nsslapd-pluginpath: libipa_pwd_extop add nsslapd-plugininitfunc: ipapwd_init add nsslapd-plugintype: extendedop add nsslapd-pluginbetxn: on add nsslapd-pluginenabled: on add nsslapd-pluginid: ipa_pwd_extop add nsslapd-pluginversion: 1.0 add nsslapd-pluginvendor: RedHat add nsslapd-plugindescription: Support saving passwords in multiple formats for different consumers (krb5, samba, freeradius, etc.) add nsslapd-plugin-depends-on-type: database add nsslapd-realmTree: dc=ipa,dc=test adding new entry "cn=ipa_pwd_extop,cn=plugins,cn=config" modify complete 2020-06-03T06:35:24Z DEBUG stderr=ldap_initialize( ldapi://%2Frun%2Fslapd-IPA-TEST.socket/??base ) SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0 2020-06-03T06:35:24Z DEBUG step duration: krb5kdc __add_pwd_extop_module 0.02 sec 2020-06-03T06:35:24Z DEBUG [3/5]: creating anonymous principal 2020-06-03T06:35:24Z DEBUG step duration: krb5kdc add_anonymous_principal 0.00 sec 2020-06-03T06:35:24Z DEBUG [4/5]: starting the KDC 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'start', 'krb5kdc.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=0 2020-06-03T06:35:24Z DEBUG stdout= 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'is-active', 'krb5kdc.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=0 2020-06-03T06:35:24Z DEBUG stdout=active 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Start of krb5kdc.service complete 2020-06-03T06:35:24Z DEBUG step duration: krb5kdc __start_instance 0.06 sec 2020-06-03T06:35:24Z DEBUG [5/5]: configuring KDC to start on boot 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'is-enabled', 'krb5kdc.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=1 2020-06-03T06:35:24Z DEBUG stdout=disabled 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'disable', 'krb5kdc.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=0 2020-06-03T06:35:24Z DEBUG stdout= 2020-06-03T06:35:24Z DEBUG stderr=Synchronizing state of krb5kdc.service with SysV service script with /lib/systemd/systemd-sysv-install. Executing: /lib/systemd/systemd-sysv-install disable krb5kdc 2020-06-03T06:35:24Z DEBUG step duration: krb5kdc __enable 0.37 sec 2020-06-03T06:35:24Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2020-06-03T06:35:24Z DEBUG service duration: krb5kdc 0.49 sec 2020-06-03T06:35:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:24Z DEBUG Configuring kadmin 2020-06-03T06:35:24Z DEBUG [1/2]: starting kadmin 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'is-active', 'kadmin.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=3 2020-06-03T06:35:24Z DEBUG stdout=inactive 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'restart', 'kadmin.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=0 2020-06-03T06:35:24Z DEBUG stdout= 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'is-active', 'kadmin.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=0 2020-06-03T06:35:24Z DEBUG stdout=active 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Restart of kadmin.service complete 2020-06-03T06:35:24Z DEBUG step duration: kadmin __start 0.06 sec 2020-06-03T06:35:24Z DEBUG [2/2]: configuring kadmin to start on boot 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'is-enabled', 'kadmin.service'] 2020-06-03T06:35:24Z DEBUG Process finished, return code=1 2020-06-03T06:35:24Z DEBUG stdout=disabled 2020-06-03T06:35:24Z DEBUG stderr= 2020-06-03T06:35:24Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:24Z DEBUG Starting external process 2020-06-03T06:35:24Z DEBUG args=['/sbin/systemctl', 'disable', 'kadmin.service'] 2020-06-03T06:35:25Z DEBUG Process finished, return code=0 2020-06-03T06:35:25Z DEBUG stdout= 2020-06-03T06:35:25Z DEBUG stderr=Synchronizing state of kadmin.service with SysV service script with /lib/systemd/systemd-sysv-install. Executing: /lib/systemd/systemd-sysv-install disable kadmin 2020-06-03T06:35:25Z DEBUG step duration: kadmin __enable 0.35 sec 2020-06-03T06:35:25Z DEBUG Done configuring kadmin. 2020-06-03T06:35:25Z DEBUG service duration: kadmin 0.41 sec 2020-06-03T06:35:25Z DEBUG Backing up system configuration file '/etc/ipa/default.conf' 2020-06-03T06:35:25Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:25Z DEBUG Writing configuration file /etc/ipa/default.conf 2020-06-03T06:35:25Z DEBUG [global] basedn = dc=ipa,dc=test host = replica1.ipa.test realm = IPA.TEST domain = ipa.test xmlrpc_uri = https://master1.ipa.test/ipa/xml ldap_uri = ldapi://%2Frun%2Fslapd-IPA-TEST.socket mode = production enable_ra = True ra_plugin = dogtag dogtag_version = 10 2020-06-03T06:35:25Z DEBUG Configuring directory server (dirsrv) 2020-06-03T06:35:25Z DEBUG [1/3]: configuring TLS for DS instance 2020-06-03T06:35:25Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:25Z DEBUG Starting external process 2020-06-03T06:35:25Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-IPA-TEST/', '-L', '-n', 'IPA.TEST IPA CA', '-a', '-f', '/etc/dirsrv/slapd-IPA-TEST/pwdfile.txt'] 2020-06-03T06:35:25Z DEBUG Process finished, return code=255 2020-06-03T06:35:25Z DEBUG stdout= 2020-06-03T06:35:25Z DEBUG stderr=certutil: Could not find cert: IPA.TEST IPA CA : PR_FILE_NOT_FOUND_ERROR: File not found 2020-06-03T06:35:25Z DEBUG Starting external process 2020-06-03T06:35:25Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-IPA-TEST/', '-N', '-f', '/etc/dirsrv/slapd-IPA-TEST/pwdfile.txt', '-@', '/etc/dirsrv/slapd-IPA-TEST/pwdfile.txt'] 2020-06-03T06:35:25Z DEBUG Process finished, return code=0 2020-06-03T06:35:25Z DEBUG stdout= 2020-06-03T06:35:25Z DEBUG stderr= 2020-06-03T06:35:25Z DEBUG Starting external process 2020-06-03T06:35:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:25Z DEBUG Process finished, return code=1 2020-06-03T06:35:25Z DEBUG stdout= 2020-06-03T06:35:25Z DEBUG stderr= 2020-06-03T06:35:25Z DEBUG Starting external process 2020-06-03T06:35:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:25Z DEBUG Process finished, return code=1 2020-06-03T06:35:25Z DEBUG stdout= 2020-06-03T06:35:25Z DEBUG stderr= 2020-06-03T06:35:25Z DEBUG Starting external process 2020-06-03T06:35:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:25Z DEBUG Process finished, return code=1 2020-06-03T06:35:25Z DEBUG stdout= 2020-06-03T06:35:25Z DEBUG stderr= 2020-06-03T06:35:25Z DEBUG Starting external process 2020-06-03T06:35:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:25Z DEBUG Process finished, return code=1 2020-06-03T06:35:25Z DEBUG stdout= 2020-06-03T06:35:25Z DEBUG stderr= 2020-06-03T06:35:25Z DEBUG Starting external process 2020-06-03T06:35:25Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:25Z DEBUG Process finished, return code=1 2020-06-03T06:35:25Z DEBUG stdout= 2020-06-03T06:35:25Z DEBUG stderr= 2020-06-03T06:35:25Z DEBUG Starting external process 2020-06-03T06:35:25Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-IPA-TEST/', '-A', '-n', 'IPA.TEST IPA CA', '-t', 'CT,C,C', '-a', '-f', '/etc/dirsrv/slapd-IPA-TEST/pwdfile.txt'] 2020-06-03T06:35:25Z DEBUG Process finished, return code=0 2020-06-03T06:35:25Z DEBUG stdout= 2020-06-03T06:35:25Z DEBUG stderr= 2020-06-03T06:35:25Z DEBUG certmonger request is in state dbus.String('NEWLY_ADDED_READING_KEYINFO', variant_level=1) 2020-06-03T06:35:30Z DEBUG certmonger request is in state dbus.String('POST_SAVED_CERT', variant_level=1) 2020-06-03T06:35:35Z DEBUG certmonger request is in state dbus.String('POST_SAVED_CERT', variant_level=1) 2020-06-03T06:35:40Z DEBUG certmonger request is in state dbus.String('MONITORING', variant_level=1) 2020-06-03T06:35:40Z DEBUG Cert request 20200603063525 was successful 2020-06-03T06:35:40Z DEBUG Destroyed connection context.ldap2_140690310172784 2020-06-03T06:35:40Z DEBUG Created connection context.ldap2_140690310172784 2020-06-03T06:35:40Z DEBUG Starting external process 2020-06-03T06:35:40Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-IPA-TEST/', '-L', '-n', 'Server-Cert', '-a', '-f', '/etc/dirsrv/slapd-IPA-TEST/pwdfile.txt'] 2020-06-03T06:35:40Z DEBUG Process finished, return code=0 2020-06-03T06:35:40Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIFFTCCA32gAwIBAgIBCzANBgkqhkiG9w0BAQsFADAzMREwDwYDVQQKDAhJUEEu VEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTIwMDYwMzA2 MzUyOFoXDTIyMDYwNDA2MzUyOFowLzERMA8GA1UECgwISVBBLlRFU1QxGjAYBgNV BAMMEXJlcGxpY2ExLmlwYS50ZXN0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB CgKCAQEAnpix6F4ts/lQL16f69AaEeipFdvlbc3P+UheN8OIVgpURInh8xHI4NwD 9wckufHxx0Kp7eN5H92IZAdccMgFQS3hL8YsfMKWXBpwoC2+RfPp45U+61Ra3kdk Z9GhDqcHaLoVpe7bJbGUlFcTQs/boWhrRf9F0C97w0nyWV/T621ZoF25cEpUIw0K plhxJarAv5Khl+WgtacRvE4dftVHvFOAictZOK5Y6M4eJtLXeupGUKklteLxTK7X dmwwWsPl0H9Snhx8tYCxmkSwRxtPGmJsTBLEeOagVOwTPUV3w770mN+8/N2AtaSw nWtNV21+kUqFXLRfZNqnp2T6FearywIDAQABo4IBtjCCAbIwHwYDVR0jBBgwFoAU Q9d4f9VJNVwSwUgHPucY3+9QdlUwOgYIKwYBBQUHAQEELjAsMCoGCCsGAQUFBzAB hh5odHRwOi8vaXBhLWNhLmlwYS50ZXN0L2NhL29jc3AwDgYDVR0PAQH/BAQDAgTw MB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjBzBgNVHR8EbDBqMGigMKAu hixodHRwOi8vaXBhLWNhLmlwYS50ZXN0L2lwYS9jcmwvTWFzdGVyQ1JMLmJpbqI0 pDIwMDEOMAwGA1UECgwFaXBhY2ExHjAcBgNVBAMMFUNlcnRpZmljYXRlIEF1dGhv cml0eTAdBgNVHQ4EFgQUN+TTbc4cYt3oNj5NSzcoIy39tUYwgY8GA1UdEQSBhzCB hIIRcmVwbGljYTEuaXBhLnRlc3SgLwYKKwYBBAGCNxQCA6AhDB9sZGFwL3JlcGxp Y2ExLmlwYS50ZXN0QElQQS5URVNUoD4GBisGAQUCAqA0MDKgChsISVBBLlRFU1Sh JDAioAMCAQGhGzAZGwRsZGFwGxFyZXBsaWNhMS5pcGEudGVzdDANBgkqhkiG9w0B AQsFAAOCAYEAXuzlrn5J/r12JJGXYfHc6ZEGL6UbrHcbftNUCKNOLcgNVRKkYuTs VA5FiBsY0QvO49vqhxF+N2kAnDgYwQVNJupsANpvWD1YGrID2q8TBsgBThki2uju 4th60XJMv0fdL53z8yG2plIKNRYen1iJWilnbJ/fKB2uLmKgpQyL0habMQF8XL42 /lYneDTrFqU14BOPUZe3LQW9uRxxXi4OKXkz5nlsaPWdS/NggjgtUC7siVy+sgKr OL1sOcqy624gTtPPTLZrwvBACHRgo+RDFJfkBdwZzWY1xHSe/kpgBfHSmt/+RMMj YanKoS82bLcmkbZwvKyLId+oWvhDUE02qIo4/Kajr32qZ2MYK6/cEG2GEuoqFxoi 526+Xr88XhHHXW9wrZOKRhEJjcuP92+/MM9y1Wk1BvC9HX4tHVATwvsaVLESlSDh NNXuZMSLrjJR+eUM+WIWK9a8Snhx8hKErF0wnToy5XzMYQwD0HXHuv7OEaUB7uxj J9ERaoss3598 -----END CERTIFICATE----- 2020-06-03T06:35:40Z DEBUG stderr= 2020-06-03T06:35:40Z DEBUG step duration: dirsrv __enable_ssl 15.68 sec 2020-06-03T06:35:40Z DEBUG [2/3]: importing CA certificates from LDAP 2020-06-03T06:35:40Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:40Z DEBUG Starting external process 2020-06-03T06:35:40Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-IPA-TEST/', '-A', '-n', 'IPA.TEST IPA CA', '-t', 'CT,C,C', '-a', '-f', '/etc/dirsrv/slapd-IPA-TEST/pwdfile.txt'] 2020-06-03T06:35:40Z DEBUG Process finished, return code=0 2020-06-03T06:35:40Z DEBUG stdout= 2020-06-03T06:35:40Z DEBUG stderr= 2020-06-03T06:35:40Z DEBUG step duration: dirsrv __import_ca_certs 0.02 sec 2020-06-03T06:35:40Z DEBUG [3/3]: restarting directory server 2020-06-03T06:35:40Z DEBUG Destroyed connection context.ldap2_140690310172784 2020-06-03T06:35:40Z DEBUG Starting external process 2020-06-03T06:35:40Z DEBUG args=['/sbin/systemctl', '--system', 'daemon-reload'] 2020-06-03T06:35:40Z DEBUG Process finished, return code=0 2020-06-03T06:35:40Z DEBUG stdout= 2020-06-03T06:35:40Z DEBUG stderr= 2020-06-03T06:35:40Z DEBUG Starting external process 2020-06-03T06:35:40Z DEBUG args=['/sbin/systemctl', 'restart', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout= 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['/sbin/systemctl', 'is-active', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=active 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG wait_for_open_ports: localhost [389] timeout 120 2020-06-03T06:35:46Z DEBUG waiting for port: 389 2020-06-03T06:35:46Z DEBUG SUCCESS: port: 389 2020-06-03T06:35:46Z DEBUG Restart of dirsrv@IPA-TEST.service complete 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['/sbin/systemctl', 'is-active', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=active 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Created connection context.ldap2_140690310172784 2020-06-03T06:35:46Z DEBUG step duration: dirsrv __restart_instance 5.49 sec 2020-06-03T06:35:46Z DEBUG Done configuring directory server (dirsrv). 2020-06-03T06:35:46Z DEBUG service duration: dirsrv 21.19 sec 2020-06-03T06:35:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:46Z DEBUG Configuring the web interface (httpd) 2020-06-03T06:35:46Z DEBUG [1/23]: stopping httpd 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['/sbin/systemctl', 'is-active', 'httpd2.service'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=3 2020-06-03T06:35:46Z DEBUG stdout=inactive 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:46Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['/sbin/systemctl', 'stop', 'httpd2.service'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout= 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Stop of httpd2.service complete 2020-06-03T06:35:46Z DEBUG step duration: httpd __stop 0.03 sec 2020-06-03T06:35:46Z DEBUG [2/23]: backing up ssl.conf 2020-06-03T06:35:46Z DEBUG Backing up system configuration file '/etc/httpd2/conf/sites-available/default_https.conf' 2020-06-03T06:35:46Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:46Z DEBUG Backing up system configuration file '/etc/httpd2/conf/sites-available/default_https.conf' 2020-06-03T06:35:46Z DEBUG -> Not backing up - already have a copy of '/etc/httpd2/conf/sites-available/default_https.conf' 2020-06-03T06:35:46Z DEBUG step duration: httpd backup_ssl_conf 0.00 sec 2020-06-03T06:35:46Z DEBUG [3/23]: disabling nss.conf 2020-06-03T06:35:46Z DEBUG step duration: httpd disable_nss_conf 0.00 sec 2020-06-03T06:35:46Z DEBUG [4/23]: configuring mod_ssl certificate paths 2020-06-03T06:35:46Z DEBUG step duration: httpd configure_mod_ssl_certs 0.00 sec 2020-06-03T06:35:46Z DEBUG [5/23]: setting mod_ssl protocol list 2020-06-03T06:35:46Z DEBUG step duration: httpd set_mod_ssl_protocol 0.00 sec 2020-06-03T06:35:46Z DEBUG [6/23]: configuring mod_ssl log directory 2020-06-03T06:35:46Z DEBUG step duration: httpd set_mod_ssl_logdir 0.00 sec 2020-06-03T06:35:46Z DEBUG [7/23]: disabling alt mod_ssl defaults 2020-06-03T06:35:46Z DEBUG step duration: httpd disable_mod_ssl_alt_defaults 0.00 sec 2020-06-03T06:35:46Z DEBUG [8/23]: disabling mod_ssl OCSP 2020-06-03T06:35:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:35:46Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:35:46Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:35:46Z DEBUG step duration: httpd disable_mod_ssl_ocsp 0.02 sec 2020-06-03T06:35:46Z DEBUG [9/23]: adding URL rewriting rules 2020-06-03T06:35:46Z DEBUG step duration: httpd __add_include 0.00 sec 2020-06-03T06:35:46Z DEBUG [10/23]: configuring httpd 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=1 2020-06-03T06:35:46Z DEBUG stdout= 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['/sbin/systemctl', '--system', 'daemon-reload'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout= 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z INFO Nothing to do for configure_httpd_wsgi_conf 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=1 2020-06-03T06:35:46Z DEBUG stdout= 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Backing up system configuration file '/etc/httpd2/conf/sites-available/ipa.conf' 2020-06-03T06:35:46Z DEBUG -> Not backing up - '/etc/httpd2/conf/sites-available/ipa.conf' doesn't exist 2020-06-03T06:35:46Z DEBUG Backing up system configuration file '/etc/httpd2/conf/extra-enabled/ipa-rewrite.conf' 2020-06-03T06:35:46Z DEBUG -> Not backing up - '/etc/httpd2/conf/extra-enabled/ipa-rewrite.conf' doesn't exist 2020-06-03T06:35:46Z DEBUG step duration: httpd __configure_http 0.15 sec 2020-06-03T06:35:46Z DEBUG [11/23]: configuring httpd modules 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2dismod', 'nss'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=1 2020-06-03T06:35:46Z DEBUG stdout=Module nss does not exist! 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'ssl'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module ssl installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'auth_gssapi'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module auth_gssapi installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'rewrite'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module rewrite installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'filter'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module filter installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'deflate'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module deflate installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'headers'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module headers installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'authn_core'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module authn_core installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'authz_user'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module authz_user installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'expires'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module expires installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'lookup_identity'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module lookup_identity installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'session'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module session installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'session_cookie'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module session_cookie installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'proxy_ajp'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Enabling proxy as a dependency Module proxy installed; run service httpd2 condreload to fully enable. Module proxy_ajp installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'proxy_http'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Enabling proxy as a dependency Module proxy is already enabled! Module proxy installed; run service httpd2 condreload to fully enable. Module proxy_http installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'proxy'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module proxy is already enabled! Module proxy installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2dismod', 'wsgi'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=1 2020-06-03T06:35:46Z DEBUG stdout=Module wsgi does not exist! 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2enmod', 'wsgi-py3'] 2020-06-03T06:35:46Z DEBUG Process finished, return code=0 2020-06-03T06:35:46Z DEBUG stdout=Module wsgi-py3 installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:46Z DEBUG stderr= 2020-06-03T06:35:46Z DEBUG Backing up system configuration file '/etc/httpd2/conf/sites-start.d/000-default.conf' 2020-06-03T06:35:46Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:46Z DEBUG Starting external process 2020-06-03T06:35:46Z DEBUG args=['a2chkconfig'] 2020-06-03T06:35:47Z DEBUG Process finished, return code=0 2020-06-03T06:35:47Z DEBUG stdout=Port config http.conf is already enabled! Extra config httpd-addon.d.conf is already disabled, or does not exist! Extra config httpd-autoindex.conf is already enabled! Extra config httpd-default.conf is already enabled! Extra config httpd-icons.conf is already enabled! Extra config httpd-languages.conf is already enabled! Extra config httpd-mime.conf is already enabled! Extra config httpd-mpm.conf is already enabled! Extra config httpd-multilang-errordoc.conf is already enabled! Site default disabled; run service httpd2 condreload to fully disable. Site config .confThis site is already enabled! Site config .conf is already disabled, or does not exist! Module access_compat is already enabled! Module access_compat installed; run service httpd2 condreload to fully enable. Module alias is already enabled! Module alias installed; run service httpd2 condreload to fully enable. Module authz_core is already enabled! Module authz_core installed; run service httpd2 condreload to fully enable. Module authz_host is already enabled! Module authz_host installed; run service httpd2 condreload to fully enable. Module autoindex is already enabled! Module autoindex installed; run service httpd2 condreload to fully enable. Module dir is already enabled! Module dir installed; run service httpd2 condreload to fully enable. Module include is already enabled! Module include installed; run service httpd2 condreload to fully enable. Module log_config is already enabled! Module log_config installed; run service httpd2 condreload to fully enable. Module logio is already enabled! Module logio installed; run service httpd2 condreload to fully enable. Module mime is already enabled! Module mime installed; run service httpd2 condreload to fully enable. Module negotiation is already enabled! Module negotiation installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:47Z DEBUG stderr= 2020-06-03T06:35:47Z DEBUG Starting external process 2020-06-03T06:35:47Z DEBUG args=['a2enport', 'https'] 2020-06-03T06:35:47Z DEBUG Process finished, return code=0 2020-06-03T06:35:47Z DEBUG stdout=Port config https installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:47Z DEBUG stderr= 2020-06-03T06:35:47Z DEBUG Starting external process 2020-06-03T06:35:47Z DEBUG args=['a2ensite', 'default_https'] 2020-06-03T06:35:47Z DEBUG Process finished, return code=0 2020-06-03T06:35:47Z DEBUG stdout=Site default_https installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:47Z DEBUG stderr= 2020-06-03T06:35:47Z DEBUG Starting external process 2020-06-03T06:35:47Z DEBUG args=['a2ensite', 'ipa'] 2020-06-03T06:35:47Z DEBUG Process finished, return code=0 2020-06-03T06:35:47Z DEBUG stdout=Site ipa installed; run service httpd2 condreload to fully enable. 2020-06-03T06:35:47Z DEBUG stderr= 2020-06-03T06:35:47Z DEBUG step duration: httpd configure_httpd_mods 0.53 sec 2020-06-03T06:35:47Z DEBUG [12/23]: setting up httpd keytab 2020-06-03T06:35:47Z DEBUG raw: service_add('HTTP/replica1.ipa.test@IPA.TEST', force=True, version='2.236') 2020-06-03T06:35:47Z DEBUG service_add(ipapython.kerberos.Principal('HTTP/replica1.ipa.test@IPA.TEST'), force=True, skip_host_check=False, all=False, raw=False, version='2.236', no_members=False) 2020-06-03T06:35:47Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:35:47Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:35:47Z DEBUG raw: host_show('replica1.ipa.test', version='2.236') 2020-06-03T06:35:47Z DEBUG host_show('replica1.ipa.test', rights=False, all=False, raw=False, version='2.236', no_members=False) 2020-06-03T06:35:47Z DEBUG Backing up system configuration file '/var/lib/ipa/gssproxy/http.keytab' 2020-06-03T06:35:47Z DEBUG -> Not backing up - '/var/lib/ipa/gssproxy/http.keytab' doesn't exist 2020-06-03T06:35:47Z DEBUG Starting external process 2020-06-03T06:35:47Z DEBUG args=['/usr/sbin/ipa-getkeytab', '-k', '/var/lib/ipa/gssproxy/http.keytab', '-p', 'HTTP/replica1.ipa.test@IPA.TEST', '-H', 'ldapi://%2Frun%2Fslapd-IPA-TEST.socket', '-Y', 'EXTERNAL'] 2020-06-03T06:35:47Z DEBUG Process finished, return code=0 2020-06-03T06:35:47Z DEBUG stdout= 2020-06-03T06:35:47Z DEBUG stderr=Keytab successfully retrieved and stored in: /var/lib/ipa/gssproxy/http.keytab 2020-06-03T06:35:48Z DEBUG Waiting up to 300 seconds for replication (ldap://master1.ipa.test:389) krbprincipalname=HTTP/replica1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test (objectclass=*) 2020-06-03T06:35:49Z DEBUG Entry found [LDAPEntry(ipapython.dn.DN('krbprincipalname=HTTP/replica1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test'), {'krbLastPwdChange': [b'20200603063547Z'], 'krbCanonicalName': [b'HTTP/replica1.ipa.test@IPA.TEST'], 'objectClass': [b'krbprincipal', b'krbprincipalaux', b'krbticketpolicyaux', b'ipaobject', b'ipaservice', b'pkiuser', b'ipakrbprincipal', b'top'], 'managedBy': [b'fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test'], 'ipaKrbPrincipalAlias': [b'HTTP/replica1.ipa.test@IPA.TEST'], 'krbPrincipalName': [b'HTTP/replica1.ipa.test@IPA.TEST'], 'ipaUniqueID': [b'75b7f5fa-a564-11ea-b5ac-0242ac120004']})] 2020-06-03T06:35:49Z DEBUG step duration: httpd request_service_keytab 1.97 sec 2020-06-03T06:35:49Z DEBUG [13/23]: configuring Gssproxy 2020-06-03T06:35:49Z DEBUG Starting external process 2020-06-03T06:35:49Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:49Z DEBUG Process finished, return code=1 2020-06-03T06:35:49Z DEBUG stdout= 2020-06-03T06:35:49Z DEBUG stderr= 2020-06-03T06:35:49Z DEBUG Starting external process 2020-06-03T06:35:49Z DEBUG args=['/sbin/systemctl', 'restart', 'gssproxy.service'] 2020-06-03T06:35:49Z DEBUG Process finished, return code=0 2020-06-03T06:35:49Z DEBUG stdout= 2020-06-03T06:35:49Z DEBUG stderr= 2020-06-03T06:35:49Z DEBUG Starting external process 2020-06-03T06:35:49Z DEBUG args=['/sbin/systemctl', 'is-active', 'gssproxy.service'] 2020-06-03T06:35:49Z DEBUG Process finished, return code=0 2020-06-03T06:35:49Z DEBUG stdout=active 2020-06-03T06:35:49Z DEBUG stderr= 2020-06-03T06:35:49Z DEBUG Restart of gssproxy.service complete 2020-06-03T06:35:49Z DEBUG step duration: httpd configure_gssproxy 0.06 sec 2020-06-03T06:35:49Z DEBUG [14/23]: setting up ssl 2020-06-03T06:35:49Z DEBUG certmonger request is in state dbus.String('GENERATING_KEY_PAIR', variant_level=1) 2020-06-03T06:35:54Z DEBUG certmonger request is in state dbus.String('MONITORING', variant_level=1) 2020-06-03T06:35:54Z DEBUG Cert request 20200603063549 was successful 2020-06-03T06:35:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:35:54Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:35:54Z DEBUG step duration: httpd __setup_ssl 5.04 sec 2020-06-03T06:35:54Z DEBUG [15/23]: configure certmonger for renewals 2020-06-03T06:35:54Z DEBUG Starting external process 2020-06-03T06:35:54Z DEBUG args=['/sbin/systemctl', 'is-active', 'certmonger.service'] 2020-06-03T06:35:54Z DEBUG Process finished, return code=0 2020-06-03T06:35:54Z DEBUG stdout=active 2020-06-03T06:35:54Z DEBUG stderr= 2020-06-03T06:35:54Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:54Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:54Z DEBUG step duration: httpd configure_certmonger_renewal_guard 0.10 sec 2020-06-03T06:35:54Z DEBUG [16/23]: publish CA cert 2020-06-03T06:35:54Z DEBUG step duration: httpd __publish_ca_cert 0.01 sec 2020-06-03T06:35:54Z DEBUG [17/23]: clean up any existing httpd ccaches 2020-06-03T06:35:54Z DEBUG step duration: httpd remove_httpd_ccaches 0.00 sec 2020-06-03T06:35:54Z DEBUG [18/23]: configuring SELinux for httpd 2020-06-03T06:35:54Z DEBUG Starting external process 2020-06-03T06:35:54Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:35:54Z DEBUG Process finished, return code=1 2020-06-03T06:35:54Z DEBUG stdout= 2020-06-03T06:35:54Z DEBUG stderr= 2020-06-03T06:35:54Z DEBUG step duration: httpd configure_selinux_for_httpd 0.02 sec 2020-06-03T06:35:54Z DEBUG [19/23]: create KDC proxy config 2020-06-03T06:35:54Z DEBUG Backing up system configuration file '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' 2020-06-03T06:35:54Z DEBUG -> Not backing up - '/etc/ipa/kdcproxy/ipa-kdc-proxy.conf' doesn't exist 2020-06-03T06:35:54Z DEBUG step duration: httpd create_kdcproxy_conf 0.00 sec 2020-06-03T06:35:54Z DEBUG [20/23]: enable KDC proxy 2020-06-03T06:35:54Z DEBUG service KDC has all config values set 2020-06-03T06:35:54Z DEBUG step duration: httpd enable_kdcproxy 0.01 sec 2020-06-03T06:35:54Z DEBUG [21/23]: starting httpd 2020-06-03T06:35:54Z DEBUG Starting external process 2020-06-03T06:35:54Z DEBUG args=['/sbin/systemctl', 'start', 'httpd2.service'] 2020-06-03T06:35:57Z DEBUG Process finished, return code=0 2020-06-03T06:35:57Z DEBUG stdout= 2020-06-03T06:35:57Z DEBUG stderr= 2020-06-03T06:35:57Z DEBUG Starting external process 2020-06-03T06:35:57Z DEBUG args=['/sbin/systemctl', 'is-active', 'httpd2.service'] 2020-06-03T06:35:57Z DEBUG Process finished, return code=0 2020-06-03T06:35:57Z DEBUG stdout=active 2020-06-03T06:35:57Z DEBUG stderr= 2020-06-03T06:35:57Z DEBUG Start of httpd2.service complete 2020-06-03T06:35:57Z DEBUG step duration: httpd start 3.24 sec 2020-06-03T06:35:57Z DEBUG [22/23]: configuring httpd to start on boot 2020-06-03T06:35:57Z DEBUG Starting external process 2020-06-03T06:35:57Z DEBUG args=['/sbin/systemctl', 'is-enabled', 'httpd2.service'] 2020-06-03T06:35:57Z DEBUG Process finished, return code=1 2020-06-03T06:35:57Z DEBUG stdout=disabled 2020-06-03T06:35:57Z DEBUG stderr= 2020-06-03T06:35:57Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:57Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:57Z DEBUG Starting external process 2020-06-03T06:35:57Z DEBUG args=['/sbin/systemctl', 'disable', 'httpd2.service'] 2020-06-03T06:35:58Z DEBUG Process finished, return code=0 2020-06-03T06:35:58Z DEBUG stdout= 2020-06-03T06:35:58Z DEBUG stderr=Synchronizing state of httpd2.service with SysV service script with /lib/systemd/systemd-sysv-install. Executing: /lib/systemd/systemd-sysv-install disable httpd2 2020-06-03T06:35:58Z DEBUG step duration: httpd __enable 0.97 sec 2020-06-03T06:35:58Z DEBUG [23/23]: enabling oddjobd 2020-06-03T06:35:58Z DEBUG Starting external process 2020-06-03T06:35:58Z DEBUG args=['/sbin/systemctl', 'is-active', 'oddjobd.service'] 2020-06-03T06:35:58Z DEBUG Process finished, return code=3 2020-06-03T06:35:58Z DEBUG stdout=inactive 2020-06-03T06:35:58Z DEBUG stderr= 2020-06-03T06:35:58Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:58Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:58Z DEBUG Starting external process 2020-06-03T06:35:58Z DEBUG args=['/sbin/systemctl', 'is-enabled', 'oddjobd.service'] 2020-06-03T06:35:58Z DEBUG Process finished, return code=1 2020-06-03T06:35:58Z DEBUG stdout=disabled 2020-06-03T06:35:58Z DEBUG stderr= 2020-06-03T06:35:58Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:58Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:58Z DEBUG Starting external process 2020-06-03T06:35:58Z DEBUG args=['/sbin/systemctl', 'enable', 'oddjobd.service'] 2020-06-03T06:35:59Z DEBUG Process finished, return code=0 2020-06-03T06:35:59Z DEBUG stdout= 2020-06-03T06:35:59Z DEBUG stderr=Synchronizing state of oddjobd.service with SysV service script with /lib/systemd/systemd-sysv-install. Executing: /lib/systemd/systemd-sysv-install enable oddjobd Created symlink /etc/systemd/system/multi-user.target.wants/oddjobd.service → /lib/systemd/system/oddjobd.service. 2020-06-03T06:35:59Z DEBUG Starting external process 2020-06-03T06:35:59Z DEBUG args=['/sbin/systemctl', 'start', 'oddjobd.service'] 2020-06-03T06:35:59Z DEBUG Process finished, return code=0 2020-06-03T06:35:59Z DEBUG stdout= 2020-06-03T06:35:59Z DEBUG stderr= 2020-06-03T06:35:59Z DEBUG Starting external process 2020-06-03T06:35:59Z DEBUG args=['/sbin/systemctl', 'is-active', 'oddjobd.service'] 2020-06-03T06:35:59Z DEBUG Process finished, return code=0 2020-06-03T06:35:59Z DEBUG stdout=active 2020-06-03T06:35:59Z DEBUG stderr= 2020-06-03T06:35:59Z DEBUG Start of oddjobd.service complete 2020-06-03T06:35:59Z DEBUG step duration: httpd enable_and_start_oddjobd 0.85 sec 2020-06-03T06:35:59Z DEBUG Done configuring the web interface (httpd). 2020-06-03T06:35:59Z DEBUG service duration: httpd 13.01 sec 2020-06-03T06:35:59Z DEBUG Backing up system configuration file '/etc/ipa/default.conf' 2020-06-03T06:35:59Z DEBUG Saving Index File to '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:59Z DEBUG Writing configuration file /etc/ipa/default.conf 2020-06-03T06:35:59Z DEBUG [global] basedn = dc=ipa,dc=test host = replica1.ipa.test realm = IPA.TEST domain = ipa.test xmlrpc_uri = https://replica1.ipa.test/ipa/xml ldap_uri = ldapi://%2Frun%2Fslapd-IPA-TEST.socket mode = production enable_ra = True ra_plugin = dogtag dogtag_version = 10 2020-06-03T06:35:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:59Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:59Z DEBUG Configuring ipa-otpd 2020-06-03T06:35:59Z DEBUG [1/2]: starting ipa-otpd 2020-06-03T06:35:59Z DEBUG Starting external process 2020-06-03T06:35:59Z DEBUG args=['/sbin/systemctl', 'is-active', 'ipa-otpd.socket'] 2020-06-03T06:35:59Z DEBUG Process finished, return code=3 2020-06-03T06:35:59Z DEBUG stdout=inactive 2020-06-03T06:35:59Z DEBUG stderr= 2020-06-03T06:35:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:59Z DEBUG Starting external process 2020-06-03T06:35:59Z DEBUG args=['/sbin/systemctl', 'restart', 'ipa-otpd.socket'] 2020-06-03T06:35:59Z DEBUG Process finished, return code=0 2020-06-03T06:35:59Z DEBUG stdout= 2020-06-03T06:35:59Z DEBUG stderr= 2020-06-03T06:35:59Z DEBUG Starting external process 2020-06-03T06:35:59Z DEBUG args=['/sbin/systemctl', 'is-active', 'ipa-otpd.socket'] 2020-06-03T06:35:59Z DEBUG Process finished, return code=0 2020-06-03T06:35:59Z DEBUG stdout=active 2020-06-03T06:35:59Z DEBUG stderr= 2020-06-03T06:35:59Z DEBUG Restart of ipa-otpd.socket complete 2020-06-03T06:35:59Z DEBUG step duration: ipa-otpd __start 0.10 sec 2020-06-03T06:35:59Z DEBUG [2/2]: configuring ipa-otpd to start on boot 2020-06-03T06:35:59Z DEBUG Starting external process 2020-06-03T06:35:59Z DEBUG args=['/sbin/systemctl', 'is-enabled', 'ipa-otpd.socket'] 2020-06-03T06:35:59Z DEBUG Process finished, return code=1 2020-06-03T06:35:59Z DEBUG stdout=disabled 2020-06-03T06:35:59Z DEBUG stderr= 2020-06-03T06:35:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:59Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:59Z DEBUG Starting external process 2020-06-03T06:35:59Z DEBUG args=['/sbin/systemctl', 'disable', 'ipa-otpd.socket'] 2020-06-03T06:35:59Z DEBUG Process finished, return code=0 2020-06-03T06:35:59Z DEBUG stdout= 2020-06-03T06:35:59Z DEBUG stderr= 2020-06-03T06:35:59Z DEBUG step duration: ipa-otpd __enable 0.25 sec 2020-06-03T06:35:59Z DEBUG Done configuring ipa-otpd. 2020-06-03T06:35:59Z DEBUG service duration: ipa-otpd 0.35 sec 2020-06-03T06:35:59Z DEBUG Custodia client for '' with promotion yes. 2020-06-03T06:35:59Z INFO Custodia uses 'master1.ipa.test' as master peer. 2020-06-03T06:35:59Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:35:59Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:35:59Z DEBUG Configuring ipa-custodia 2020-06-03T06:35:59Z DEBUG [1/4]: Generating ipa-custodia config file 2020-06-03T06:35:59Z DEBUG step duration: ipa-custodia __config_file 0.00 sec 2020-06-03T06:35:59Z DEBUG [2/4]: Generating ipa-custodia keys 2020-06-03T06:36:00Z DEBUG step duration: ipa-custodia __gen_keys 0.66 sec 2020-06-03T06:36:00Z DEBUG [3/4]: starting ipa-custodia 2020-06-03T06:36:00Z DEBUG Starting external process 2020-06-03T06:36:00Z DEBUG args=['/sbin/systemctl', 'is-active', 'ipa-custodia.service'] 2020-06-03T06:36:00Z DEBUG Process finished, return code=3 2020-06-03T06:36:00Z DEBUG stdout=inactive 2020-06-03T06:36:00Z DEBUG stderr= 2020-06-03T06:36:00Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:00Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:00Z DEBUG Starting external process 2020-06-03T06:36:00Z DEBUG args=['/sbin/systemctl', 'restart', 'ipa-custodia.service'] 2020-06-03T06:36:01Z DEBUG Process finished, return code=0 2020-06-03T06:36:01Z DEBUG stdout= 2020-06-03T06:36:01Z DEBUG stderr= 2020-06-03T06:36:01Z DEBUG Starting external process 2020-06-03T06:36:01Z DEBUG args=['/sbin/systemctl', 'is-active', 'ipa-custodia.service'] 2020-06-03T06:36:01Z DEBUG Process finished, return code=0 2020-06-03T06:36:01Z DEBUG stdout=active 2020-06-03T06:36:01Z DEBUG stderr= 2020-06-03T06:36:01Z DEBUG Restart of ipa-custodia.service complete 2020-06-03T06:36:01Z DEBUG step duration: ipa-custodia __start 1.32 sec 2020-06-03T06:36:01Z DEBUG [4/4]: configuring ipa-custodia to start on boot 2020-06-03T06:36:01Z DEBUG Starting external process 2020-06-03T06:36:01Z DEBUG args=['/sbin/systemctl', 'is-enabled', 'ipa-custodia.service'] 2020-06-03T06:36:01Z DEBUG Process finished, return code=1 2020-06-03T06:36:01Z DEBUG stdout=disabled 2020-06-03T06:36:01Z DEBUG stderr= 2020-06-03T06:36:01Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:01Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:01Z DEBUG Starting external process 2020-06-03T06:36:01Z DEBUG args=['/sbin/systemctl', 'disable', 'ipa-custodia.service'] 2020-06-03T06:36:02Z DEBUG Process finished, return code=0 2020-06-03T06:36:02Z DEBUG stdout= 2020-06-03T06:36:02Z DEBUG stderr= 2020-06-03T06:36:02Z DEBUG step duration: ipa-custodia __enable 0.42 sec 2020-06-03T06:36:02Z DEBUG Done configuring ipa-custodia. 2020-06-03T06:36:02Z DEBUG service duration: ipa-custodia 2.41 sec 2020-06-03T06:36:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:36:02Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:36:02Z DEBUG Waiting up to 300 seconds to see our keys appear on host ldap://master1.ipa.test 2020-06-03T06:36:02Z DEBUG Starting external process 2020-06-03T06:36:02Z DEBUG args=['/usr/bin/certutil', '-d', '/tmp/.private/root/tmpo18hh9sw', '-N', '-f', '/tmp/.private/root/tmpo18hh9sw/pwdfile.txt', '-@', '/tmp/.private/root/tmpo18hh9sw/pwdfile.txt'] 2020-06-03T06:36:02Z DEBUG Process finished, return code=0 2020-06-03T06:36:02Z DEBUG stdout= 2020-06-03T06:36:02Z DEBUG stderr= 2020-06-03T06:36:02Z DEBUG Starting external process 2020-06-03T06:36:02Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:36:02Z DEBUG Process finished, return code=1 2020-06-03T06:36:02Z DEBUG stdout= 2020-06-03T06:36:02Z DEBUG stderr= 2020-06-03T06:36:02Z DEBUG Starting external process 2020-06-03T06:36:02Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:36:02Z DEBUG Process finished, return code=1 2020-06-03T06:36:02Z DEBUG stdout= 2020-06-03T06:36:02Z DEBUG stderr= 2020-06-03T06:36:02Z DEBUG Starting external process 2020-06-03T06:36:02Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:36:02Z DEBUG Process finished, return code=1 2020-06-03T06:36:02Z DEBUG stdout= 2020-06-03T06:36:02Z DEBUG stderr= 2020-06-03T06:36:02Z DEBUG Starting external process 2020-06-03T06:36:02Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:36:02Z DEBUG Process finished, return code=1 2020-06-03T06:36:02Z DEBUG stdout= 2020-06-03T06:36:02Z DEBUG stderr= 2020-06-03T06:36:02Z DEBUG Starting external process 2020-06-03T06:36:02Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:36:02Z DEBUG Process finished, return code=1 2020-06-03T06:36:02Z DEBUG stdout= 2020-06-03T06:36:02Z DEBUG stderr= 2020-06-03T06:36:02Z DEBUG Starting new HTTPS connection (1): master1.ipa.test:443 2020-06-03T06:36:04Z DEBUG https://master1.ipa.test:443 "GET /ipa/keys/ca/caSigningCert%20cert-pki-ca?type=kem&value=eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZDQkMtSFM1MTIiLCJraWQiOm51bGx9.xUa2cmIJu4C53VzN77nUNlfQLrxI0cALzpme-4xi-IMZxs7ZbkRsB3ZwnlW3R8aod3GWgykJZy5-Np4_-wC6PwZBVByxVXuPAvx9B3rbCy8aQIeE1G1eubxlYVwlpDdt788bTdpftfkPLpKCqNmlTgG2S0MZ8v7CxXR11sGq5JqEVqbsT1C_0nG9nFc5Ga2MAgSUodj7jaln_pOFKf57q1dJqDnVZSVYRKWSMjatddGW2X0wa4Y9FxU5IjzDGN4SoiW31Ljbrqlij64Lx-ZYjVeC8ZtEexA-M67jpK9TnNMTQTcWJnlym8q0w7RW_PasIBBh0-aAeL_gaN_mmE_MCw.is6KFIv7JqXtvoWtBuchlQ.2Ts9-hCS2rszdGrSXr2pvM_sKIHwgylLBm5nhcpLk6vkoTtu3w8x9mYT5uONPYDZXZMdAhQjqtjczfdeaOY9x4bcFkW78ltvB8Rvr7u0fFHjLoasu9T1AamSe3Aobx7YQRhkIpJx1ztwB75RER1fQkAQ3bknlrGUhvqyD2ac73CY2bLw4cLOoiSUWgqLS_iVx0RDlCusvIjObZO0oNomeaX64FUzY85mip1T_umC5cS7z4QZcYIXKnwaj34RPN5UHvXGe3u-ZJ1lvDDrFwYEzzSx3-ciKohc480TeyeHc8_b2kDgUHcC7-T0zdF5zFRUGcDndpvxtqpLQ30xfd6R04KQtVhFxXrDVTq1-6FF6XR5UtIGlRaSS0F5-2K5GTdnB6MNXoDXLHXFIUTtFUHciqcXOa7a6MKYHN4zow4KxOkaAoe1a4cmf0yNReJVZFJa3GK-3161DFcC-XNwitp5n76dzSmBEEEYGkoNE3Xlyn3Q3rRLZ0_0PkZMuOrnF_1vQT2uVvx8I3SRVtAQgBwGbKmtE60B1lXtFYesAW7RfbmfVzH-HAUR8BI_eMUBciBsrkPFIqm4vfA6Dx9nDE-gONA0zqo6Uw8oYZkkrCopyBUJ-4D7lvReV4FPR4ZAghFn2yH0sjO50Dy6SLbIxoLRkQ.cdGV2vZ8POHp4F7DOxYfxKcYnT--5WiMoGjA9YyWXVQ HTTP/1.1" 200 7363 2020-06-03T06:36:04Z DEBUG Starting external process 2020-06-03T06:36:04Z DEBUG args=['/usr/bin/pk12util', '-d', 'sql:/tmp/.private/root/tmpo18hh9sw', '-k', '/tmp/.private/root/tmpo18hh9sw/pwdfile.txt', '-n', 'caSigningCert cert-pki-ca', '-i', '/tmp/.private/root/tmpo18hh9sw/pk12file', '-w', '/tmp/.private/root/tmpo18hh9sw/pk12pwfile'] 2020-06-03T06:36:06Z DEBUG Process finished, return code=0 2020-06-03T06:36:06Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL 2020-06-03T06:36:06Z DEBUG stderr= 2020-06-03T06:36:06Z DEBUG Starting new HTTPS connection (1): master1.ipa.test:443 2020-06-03T06:36:09Z DEBUG https://master1.ipa.test:443 "GET /ipa/keys/ca/ocspSigningCert%20cert-pki-ca?type=kem&value=eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZDQkMtSFM1MTIiLCJraWQiOm51bGx9.k9onDLgbeh4gTK5C6vwxV9MWRB6FX7FV_J2DB3ZjGHOYAp5uIOr0JkKqQ7UyzOL2P-RGDmqC3fUQeXTa2NdgzmYX_1xoLZp7vpyBRryMNUUME_TsIrCXhjLqS0MDdmnpTkIBg8abfxGTzbqC4EA54t1iJP-5Q6wZTrtmfjWjjiKpEvBLr9owEDP-vTnhcVD9L4OhBW7Z3b714DzmoWq6HaZqI0CjdoZl8UpYSsbdl5EEccSJbhgf3htUwjZZ8leIS3zfZBm0reuWZamaqxgti9vdoN_8ICxGpFExsfFQXG4fz_JqeF_RLCqVnHAoKLB8CATeNNjUpyoQnc1h6t2HaQ.aITH5GfEBTdlU4q3QcI_tA.fUKEGMTub5Z-A5lqMwsarA4HPwMfVJ8iu9Zgc1mXRdd6_vA0mdk4wcBnU2UThs7wP0B7RgiMm4V2B5PEG23qtMC3AxF5JWPbBePfuEFZ9mU8tvbQVO-tBAJNVBxnXO18M2i3ikhcsuFpPW3RFutvqsy4m-qNovoy7Q2jZhkZPvb2ADpVucv-KH2DkcaM09GJNR-NuJeMyia-pxi84LRstgBAGTzIBn6CM3zGNzfqaC5DGrwE-q8llYmlQKyDN_GVRzNlw-gMTb4vzQJ2PS6o6IqnXgIu_yQa_T6XU4oigtdi8oyDzH0tf16bm8BMhld5NqwrgbNVv7l12y4GjbZtIn7OceiwnOwrAaMZ4Le7OmgaeXwnwFsFf84Kjw5jdP_4da68T-ZzeCRSZVX-Ym5MT-ZR8RsWYYt2d22ROrDBbi7QL_nSRIzjyt8pLN2pgwUsnqy8O8nqbS8Hku6olRxH173Dd4nEAZ3dBSvFXeyt_dRydjRZKI42wHkynDNH5eRS4cG-URpfF_baUdkjKTnCWvLu8MFpeegn4Hnat471eVXvjbcssiAOHLn9rpq6Y8MB3sbeY2-Mm1BiKjMwI92JHgrFD4WepoRsM30yULEvuAIT1w_gDWQCmnRlCVS1pOX_qfr5SeQ8oB5DmBiF3AYjBQ.KduJaE4jacKEMPMiYv1a7r7_BquasniiVxJJsb1GjAc HTTP/1.1" 200 8330 2020-06-03T06:36:09Z DEBUG Starting external process 2020-06-03T06:36:09Z DEBUG args=['/usr/bin/pk12util', '-d', 'sql:/tmp/.private/root/tmpo18hh9sw', '-k', '/tmp/.private/root/tmpo18hh9sw/pwdfile.txt', '-n', 'ocspSigningCert cert-pki-ca', '-i', '/tmp/.private/root/tmpo18hh9sw/pk12file', '-w', '/tmp/.private/root/tmpo18hh9sw/pk12pwfile'] 2020-06-03T06:36:10Z DEBUG Process finished, return code=0 2020-06-03T06:36:10Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL 2020-06-03T06:36:10Z DEBUG stderr= 2020-06-03T06:36:10Z DEBUG Starting new HTTPS connection (1): master1.ipa.test:443 2020-06-03T06:36:13Z DEBUG https://master1.ipa.test:443 "GET /ipa/keys/ca/auditSigningCert%20cert-pki-ca?type=kem&value=eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZDQkMtSFM1MTIiLCJraWQiOm51bGx9.H2oRdK7Slu7DXhF7OSR8Ihi63RWj_NYXcqdyRGOwmbn3DH3uvgyF84M3cOIr6PZcc4ay5ITxWF1ztoB-laILyMHFz9jMhCwk8wkrIehabDuAqTAfHg97bHa3sVd9OCttFHoEfUoUSVQFvAliPUgbuDkxP5IqiC5w3ALjsGfDA21tTbZOl5w5iZc5WJtENla-fxGTTpchcTh9QpzgZP6TvtaO6y2KuvdGA31KRVkaBJKWqEjwA56LwtJC7nev3ePS-foCzHVttnyXgbq-idvNE-ldXfcYhy4GuEl0jW3AiYpNB654KA5j7qtY-XEku_YdFBclQzWHtMR71fnHAc1_YA.BDGt6ewljTt3Oj46z-NlEw.TmayGTYttbmLTWvE4rDdVj0Cw1vkCTXwyYCgo0WfXEr-1Ul5JhGf0svTXYFUKRAS7dcmqyRAa54J0ddVJHpl3MN9rGWlRgVondZ3fOT7wcvhN8kshoUj4iXD3F7ZGG0FcS_51gGZvKCE_3M-5fNdyekc_2_oSeFc0E6NTL6E5XeRu0JN-h-kV835Xm31FiILluNR2fkSqDDQAU5J1jo684MDjsxcIvxUaN1S-Xxfae40mFSxMYRHkQPIre1_mrOpeM0pn0YEgsv_yN_QTrGYJomTD8Y9fkf2D-X-fVrGR69dX128fFlFH2UkIP4R3rx8szSQi8w6TKi4P5b5U-G32js9faLg7LZGehFKX41d9E7KP5FpwgrDBPxzGT8xteBmT3UOjFs2KYKMkZ_zHi35o0r_dMR-SZxY_xzOw843zVq5rLu1LNTYgA9KwF8-ENeh_pLh3AoQg_qXw-ggMtcq0IxVODX34Hq69qOuA9y8SRCGZBmHqf6gmmhCxwPiMz-8pbYWrfRDM7-aftKtPKMPbY4wpKleh5KsLTMOg7nqI1wiYTVxdc5AiOwv_PMLJnGirx3MmrekGMoHm99zrcFTOIKF-rtcnfBCSH-_NwLm5Vq1Rn1bw31dcO02wB7vfMdW_4nADRdcGEmr5v1n2RADCWF5rBsp0E2GuZlCDxgSoOI.1M-0WgdXMtFh9oduzZncbKeXrosA3hJY8-e7La-i3vY HTTP/1.1" 200 8299 2020-06-03T06:36:13Z DEBUG Starting external process 2020-06-03T06:36:13Z DEBUG args=['/usr/bin/pk12util', '-d', 'sql:/tmp/.private/root/tmpo18hh9sw', '-k', '/tmp/.private/root/tmpo18hh9sw/pwdfile.txt', '-n', 'auditSigningCert cert-pki-ca', '-i', '/tmp/.private/root/tmpo18hh9sw/pk12file', '-w', '/tmp/.private/root/tmpo18hh9sw/pk12pwfile'] 2020-06-03T06:36:14Z DEBUG Process finished, return code=0 2020-06-03T06:36:14Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL 2020-06-03T06:36:14Z DEBUG stderr= 2020-06-03T06:36:14Z DEBUG Starting new HTTPS connection (1): master1.ipa.test:443 2020-06-03T06:36:17Z DEBUG https://master1.ipa.test:443 "GET /ipa/keys/ca/subsystemCert%20cert-pki-ca?type=kem&value=eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZDQkMtSFM1MTIiLCJraWQiOm51bGx9.TSJ0uiYbUwsA_6bnRhWn6QQo90ypu_9AqZkdFXXZ0YoKPPTe7QPMGAjQ-mujC6_klXmuWuumrIwp5tDq2QoZOqX1NuH_Q4G9yvnBdKXbrDGm9Hjy1GdOSPSTnxqHpFAe2xB3WEIhNapvibqMff3HeYXBoJ93_4lLRJmgL38kPKWpheV6I9esIvZFAgVd0YeuwBoNzQJFdBUT1JikNpi-1qPD3SHfAEGO0nNMl4Yrt5o6TJAut8yZCLwVZK3PgiLLRUl-a_CgE1rc1ndjyZajQBUf7_iNZ3X8uJvpr6jfMSHcE0DNUDcYkoi8gMD8EO_X5D9Pvu-mfYjhp_OHu_momA.clIWwFcyrVYwNr-cTa6kvA.iTqIPq7ChP_PWkKdvktc4cpa9mqq4MmOgg50r_VlyvInTw53odbO-XCkfRPLEFsmC_bfgcUEgOSroLyWI00GpuK9F_CvT50pT9A7ctalbQvkfU9h3gFmva_0Zxju9NKXK_8tUxw1TfGL7GuEs2g3Q1eliUwfwdxHnq8eyun1mX5SEl9tApxik4WbXgiYlHO3CDtXVZxBwMnYALpDoKmzfKCFUo_i5ZRfkmnLFTarLCkAOmhv8hVSw0ytASDWmIrz5XPJmKGM1cULH1mv4A4i3FqR3Jn7U2ZWB888mOwBimljGDhMCvItTKxROF2vmVPLAm0oZq2sgbMWLql6Ajd1cyHyxuWryckmRTZQVjKlpX96ecD3gt57QRCLittqRo72I5VYHW9ul3k83Q7zKvkoRQAG06RmjoDEB9JyOzuU9cvV105N-8mG_eT0rJ-3Pb0rpFru9hpu76iBq_dXQhmGSbQYffdZAB0MRJFSotNIxyLqWsg1fwBpW7D5HAweXYBwxm21fjU7iSzdJChRwVkg7FGqmO99i22R0WdQtxTrqdjyUVsOMW8IzYI9jXfQwYmUcjXrV0yV8bi3mHAE3V5UGfScn7O-G3X_HJHzn5cH1sovJ55flr95mfeWr2hihoxyHc5R3OZbxq8uw09jZ7id2g.i9cvbQqPoS5hR_QqyNwGehmRY0eZibO6fu7CUlS8Jvc HTTP/1.1" 200 None 2020-06-03T06:36:17Z DEBUG Starting external process 2020-06-03T06:36:17Z DEBUG args=['/usr/bin/pk12util', '-d', 'sql:/tmp/.private/root/tmpo18hh9sw', '-k', '/tmp/.private/root/tmpo18hh9sw/pwdfile.txt', '-n', 'subsystemCert cert-pki-ca', '-i', '/tmp/.private/root/tmpo18hh9sw/pk12file', '-w', '/tmp/.private/root/tmpo18hh9sw/pk12pwfile'] 2020-06-03T06:36:19Z DEBUG Process finished, return code=0 2020-06-03T06:36:19Z DEBUG stdout=pk12util: PKCS12 IMPORT SUCCESSFUL 2020-06-03T06:36:19Z DEBUG stderr= 2020-06-03T06:36:19Z DEBUG Starting external process 2020-06-03T06:36:19Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/tmp/.private/root/tmpo18hh9sw', '-A', '-n', 'IPA.TEST IPA CA', '-t', 'CT,C,C', '-a', '-f', '/tmp/.private/root/tmpo18hh9sw/pwdfile.txt'] 2020-06-03T06:36:19Z DEBUG Process finished, return code=0 2020-06-03T06:36:19Z DEBUG stdout= 2020-06-03T06:36:19Z DEBUG stderr= 2020-06-03T06:36:19Z DEBUG Starting external process 2020-06-03T06:36:19Z DEBUG args=['/usr/bin/PKCS12Export', '-d', '/tmp/.private/root/tmpo18hh9sw', '-p', '/tmp/.private/root/tmpo18hh9sw/pwdfile.txt', '-w', '/tmp/.private/root/tmpo18hh9sw/crtpwfile', '-o', '/tmp/.private/root/tmp8dmp9dtpipa/cacert.p12'] 2020-06-03T06:36:20Z DEBUG Process finished, return code=0 2020-06-03T06:36:20Z DEBUG stdout=Export complete. 2020-06-03T06:36:20Z DEBUG stderr= 2020-06-03T06:36:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:36:20Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:36:20Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:20Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:36:20Z DEBUG Configuring certificate server (pki-tomcatd). Estimated time: 3 minutes 2020-06-03T06:36:20Z DEBUG [1/30]: creating certificate server db 2020-06-03T06:36:21Z DEBUG step duration: pki-tomcatd __create_ds_db 0.08 sec 2020-06-03T06:36:21Z DEBUG [2/30]: setting up initial replication 2020-06-03T06:36:21Z DEBUG Fetching nsDS5ReplicaId from master [attempt 1/5] 2020-06-03T06:36:21Z DEBUG Successfully updated nsDS5ReplicaId. 2020-06-03T06:36:21Z DEBUG Add or update replica config cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:36:21Z DEBUG Added replica config cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:36:21Z DEBUG Fetching nsDS5ReplicaId from master [attempt 1/5] 2020-06-03T06:36:21Z DEBUG Successfully updated nsDS5ReplicaId. 2020-06-03T06:36:21Z DEBUG Add or update replica config cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:36:21Z DEBUG Added replica config cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:36:21Z DEBUG Waiting up to 300 seconds for replication (ldap://master1.ipa.test:389) cn=caToreplica1.ipa.test,cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config (objectclass=*) 2020-06-03T06:36:21Z DEBUG Entry found [LDAPEntry(ipapython.dn.DN('cn=caToreplica1.ipa.test,cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config'), {'objectClass': [b'nsds5replicationagreement', b'top'], 'cn': [b'caToreplica1.ipa.test'], 'nsDS5ReplicaHost': [b'replica1.ipa.test'], 'nsDS5ReplicaPort': [b'389'], 'nsds5replicaTimeout': [b'120'], 'nsDS5ReplicaRoot': [b'o=ipaca'], 'description': [b'me to replica1.ipa.test'], 'nsDS5ReplicatedAttributeList': [b'(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'], 'nsDS5ReplicaTransportInfo': [b'LDAP'], 'nsDS5ReplicaBindMethod': [b'SASL/GSSAPI'], 'nsds5ReplicaStripAttrs': [b'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'], 'nsDS5ReplicatedAttributeListTotal': [b'(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'], 'nsds5replicareapactive': [b'0'], 'nsds5replicaLastUpdateStart': [b'19700101000000Z'], 'nsds5replicaLastUpdateEnd': [b'19700101000000Z'], 'nsds5replicaChangesSentSinceStartup': [b''], 'nsds5replicaLastUpdateStatus': [b'Error (0) No replication sessions started since server startup'], 'nsds5replicaLastUpdateStatusJSON': [b'{"state": "green", "ldap_rc": "0", "ldap_rc_text": "success", "repl_rc": "0", "repl_rc_text": "replica acquired", "date": "2020-06-03T06:36:21Z", "message": "Error (0) No replication sessions started since server startup"}'], 'nsds5replicaUpdateInProgress': [b'FALSE'], 'nsds5replicaLastInitStart': [b'19700101000000Z'], 'nsds5replicaLastInitEnd': [b'19700101000000Z']})] 2020-06-03T06:36:21Z DEBUG Waiting up to 300 seconds for replication (ldapi://%2Frun%2Fslapd-IPA-TEST.socket) cn=caTomaster1.ipa.test,cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config (objectclass=*) 2020-06-03T06:36:21Z DEBUG Entry found [LDAPEntry(ipapython.dn.DN('cn=caTomaster1.ipa.test,cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config'), {'objectClass': [b'nsds5replicationagreement', b'top'], 'cn': [b'caTomaster1.ipa.test'], 'nsDS5ReplicaHost': [b'master1.ipa.test'], 'nsDS5ReplicaPort': [b'389'], 'nsds5replicaTimeout': [b'120'], 'nsDS5ReplicaRoot': [b'o=ipaca'], 'description': [b'me to master1.ipa.test'], 'nsDS5ReplicatedAttributeList': [b'(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'], 'nsDS5ReplicaTransportInfo': [b'LDAP'], 'nsDS5ReplicaBindMethod': [b'SASL/GSSAPI'], 'nsds5ReplicaStripAttrs': [b'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'], 'nsDS5ReplicatedAttributeListTotal': [b'(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'], 'nsds5replicareapactive': [b'0'], 'nsds5replicaLastUpdateStart': [b'19700101000000Z'], 'nsds5replicaLastUpdateEnd': [b'19700101000000Z'], 'nsds5replicaChangesSentSinceStartup': [b''], 'nsds5replicaLastUpdateStatus': [b'Error (0) No replication sessions started since server startup'], 'nsds5replicaLastUpdateStatusJSON': [b'{"state": "green", "ldap_rc": "0", "ldap_rc_text": "success", "repl_rc": "0", "repl_rc_text": "replica acquired", "date": "2020-06-03T06:36:21Z", "message": "Error (0) No replication sessions started since server startup"}'], 'nsds5replicaUpdateInProgress': [b'FALSE'], 'nsds5replicaLastInitStart': [b'19700101000000Z'], 'nsds5replicaLastInitEnd': [b'19700101000000Z']})] 2020-06-03T06:36:26Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-03T06:36:26Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-03T06:36:26Z DEBUG skipping plugin module ipaserver.plugins.dogtag: dogtag not selected as RA plugin 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-03T06:36:26Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-03T06:36:26Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-03T06:36:26Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-03T06:36:26Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-03T06:36:26Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-03T06:36:26Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-03T06:36:26Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-03T06:36:27Z DEBUG Created connection context.ldap2_140690288788240 2020-06-03T06:36:27Z DEBUG Destroyed connection context.ldap2_140690288788240 2020-06-03T06:36:27Z DEBUG Created connection context.ldap2_140690288788240 2020-06-03T06:36:27Z DEBUG Parsing update file '/usr/share/ipa/ca-topology.uldif' 2020-06-03T06:36:27Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:36:27Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:36:27Z DEBUG Updating existing entry: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG --------------------------------------------- 2020-06-03T06:36:27Z DEBUG Initial value 2020-06-03T06:36:27Z DEBUG dn: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG objectClass: 2020-06-03T06:36:27Z DEBUG top 2020-06-03T06:36:27Z DEBUG nsContainer 2020-06-03T06:36:27Z DEBUG ipaReplTopoManagedServer 2020-06-03T06:36:27Z DEBUG ipaConfigObject 2020-06-03T06:36:27Z DEBUG ipaSupportedDomainLevelConfig 2020-06-03T06:36:27Z DEBUG cn: 2020-06-03T06:36:27Z DEBUG replica1.ipa.test 2020-06-03T06:36:27Z DEBUG ipaReplTopoManagedSuffix: 2020-06-03T06:36:27Z DEBUG dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG ipaMinDomainLevel: 2020-06-03T06:36:27Z DEBUG 1 2020-06-03T06:36:27Z DEBUG ipaMaxDomainLevel: 2020-06-03T06:36:27Z DEBUG 1 2020-06-03T06:36:27Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2020-06-03T06:36:27Z DEBUG add: updated value ['top', 'nsContainer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig', 'ipaReplTopoManagedServer'] 2020-06-03T06:36:27Z DEBUG add: 'o=ipaca' to ipaReplTopoManagedSuffix, current value ['dc=ipa,dc=test'] 2020-06-03T06:36:27Z DEBUG add: updated value ['dc=ipa,dc=test', 'o=ipaca'] 2020-06-03T06:36:27Z DEBUG --------------------------------------------- 2020-06-03T06:36:27Z DEBUG Final value after applying updates 2020-06-03T06:36:27Z DEBUG dn: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG objectClass: 2020-06-03T06:36:27Z DEBUG top 2020-06-03T06:36:27Z DEBUG nsContainer 2020-06-03T06:36:27Z DEBUG ipaConfigObject 2020-06-03T06:36:27Z DEBUG ipaSupportedDomainLevelConfig 2020-06-03T06:36:27Z DEBUG ipaReplTopoManagedServer 2020-06-03T06:36:27Z DEBUG cn: 2020-06-03T06:36:27Z DEBUG replica1.ipa.test 2020-06-03T06:36:27Z DEBUG ipaReplTopoManagedSuffix: 2020-06-03T06:36:27Z DEBUG dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG o=ipaca 2020-06-03T06:36:27Z DEBUG ipaMinDomainLevel: 2020-06-03T06:36:27Z DEBUG 1 2020-06-03T06:36:27Z DEBUG ipaMaxDomainLevel: 2020-06-03T06:36:27Z DEBUG 1 2020-06-03T06:36:27Z DEBUG [(0, 'ipaReplTopoManagedSuffix', ['o=ipaca'])] 2020-06-03T06:36:27Z DEBUG Updated 1 2020-06-03T06:36:27Z DEBUG Done 2020-06-03T06:36:27Z DEBUG Updating existing entry: cn=ca,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG --------------------------------------------- 2020-06-03T06:36:27Z DEBUG Initial value 2020-06-03T06:36:27Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG cn: 2020-06-03T06:36:27Z DEBUG ca 2020-06-03T06:36:27Z DEBUG ipaReplTopoConfRoot: 2020-06-03T06:36:27Z DEBUG o=ipaca 2020-06-03T06:36:27Z DEBUG objectClass: 2020-06-03T06:36:27Z DEBUG top 2020-06-03T06:36:27Z DEBUG iparepltopoconf 2020-06-03T06:36:27Z DEBUG --------------------------------------------- 2020-06-03T06:36:27Z DEBUG Final value after applying updates 2020-06-03T06:36:27Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG cn: 2020-06-03T06:36:27Z DEBUG ca 2020-06-03T06:36:27Z DEBUG ipaReplTopoConfRoot: 2020-06-03T06:36:27Z DEBUG o=ipaca 2020-06-03T06:36:27Z DEBUG objectClass: 2020-06-03T06:36:27Z DEBUG top 2020-06-03T06:36:27Z DEBUG iparepltopoconf 2020-06-03T06:36:27Z DEBUG [] 2020-06-03T06:36:27Z DEBUG Updated 0 2020-06-03T06:36:27Z DEBUG Done 2020-06-03T06:36:27Z DEBUG Updating existing entry: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:36:27Z DEBUG --------------------------------------------- 2020-06-03T06:36:27Z DEBUG Initial value 2020-06-03T06:36:27Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:36:27Z DEBUG objectClass: 2020-06-03T06:36:27Z DEBUG top 2020-06-03T06:36:27Z DEBUG nsds5replica 2020-06-03T06:36:27Z DEBUG extensibleobject 2020-06-03T06:36:27Z DEBUG cn: 2020-06-03T06:36:27Z DEBUG replica 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaRoot: 2020-06-03T06:36:27Z DEBUG o=ipaca 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaId: 2020-06-03T06:36:27Z DEBUG 5 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaType: 2020-06-03T06:36:27Z DEBUG 3 2020-06-03T06:36:27Z DEBUG nsDS5Flags: 2020-06-03T06:36:27Z DEBUG 1 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaBindDN: 2020-06-03T06:36:27Z DEBUG cn=replication manager,cn=config 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaBindDNGroup: 2020-06-03T06:36:27Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG nsds5ReplicaLegacyConsumer: 2020-06-03T06:36:27Z DEBUG off 2020-06-03T06:36:27Z DEBUG nsds5ReplicaReleaseTimeout: 2020-06-03T06:36:27Z DEBUG 20 2020-06-03T06:36:27Z DEBUG nsds5ReplicaBackoffMax: 2020-06-03T06:36:27Z DEBUG 3 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaBindDnGroupCheckInterval: 2020-06-03T06:36:27Z DEBUG 2 2020-06-03T06:36:27Z DEBUG nsState: 2020-06-03T06:36:27Z DEBUG BQAAAAAAAADlRNdeAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAA== 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaName: 2020-06-03T06:36:27Z DEBUG 7cf5882d-a56411ea-9a6a937f-b7fd302f 2020-06-03T06:36:27Z DEBUG nsds5ReplicaChangeCount: 2020-06-03T06:36:27Z DEBUG 0 2020-06-03T06:36:27Z DEBUG nsds5replicareapactive: 2020-06-03T06:36:27Z DEBUG 0 2020-06-03T06:36:27Z DEBUG onlyifexist: 'cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test' to nsds5replicabinddngroup, current value ['cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:36:27Z DEBUG onlyifexist: set nsds5replicabinddngroup to ['cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:36:27Z DEBUG --------------------------------------------- 2020-06-03T06:36:27Z DEBUG Final value after applying updates 2020-06-03T06:36:27Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:36:27Z DEBUG objectClass: 2020-06-03T06:36:27Z DEBUG top 2020-06-03T06:36:27Z DEBUG nsds5replica 2020-06-03T06:36:27Z DEBUG extensibleobject 2020-06-03T06:36:27Z DEBUG cn: 2020-06-03T06:36:27Z DEBUG replica 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaRoot: 2020-06-03T06:36:27Z DEBUG o=ipaca 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaId: 2020-06-03T06:36:27Z DEBUG 5 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaType: 2020-06-03T06:36:27Z DEBUG 3 2020-06-03T06:36:27Z DEBUG nsDS5Flags: 2020-06-03T06:36:27Z DEBUG 1 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaBindDN: 2020-06-03T06:36:27Z DEBUG cn=replication manager,cn=config 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaBindDNGroup: 2020-06-03T06:36:27Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:36:27Z DEBUG nsds5ReplicaLegacyConsumer: 2020-06-03T06:36:27Z DEBUG off 2020-06-03T06:36:27Z DEBUG nsds5ReplicaReleaseTimeout: 2020-06-03T06:36:27Z DEBUG 20 2020-06-03T06:36:27Z DEBUG nsds5ReplicaBackoffMax: 2020-06-03T06:36:27Z DEBUG 3 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaBindDnGroupCheckInterval: 2020-06-03T06:36:27Z DEBUG 2 2020-06-03T06:36:27Z DEBUG nsState: 2020-06-03T06:36:27Z DEBUG BQAAAAAAAADlRNdeAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAA== 2020-06-03T06:36:27Z DEBUG nsDS5ReplicaName: 2020-06-03T06:36:27Z DEBUG 7cf5882d-a56411ea-9a6a937f-b7fd302f 2020-06-03T06:36:27Z DEBUG nsds5ReplicaChangeCount: 2020-06-03T06:36:27Z DEBUG 0 2020-06-03T06:36:27Z DEBUG nsds5replicareapactive: 2020-06-03T06:36:27Z DEBUG 0 2020-06-03T06:36:27Z DEBUG [] 2020-06-03T06:36:27Z DEBUG Updated 0 2020-06-03T06:36:27Z DEBUG Done 2020-06-03T06:36:27Z DEBUG LDAP update duration: /usr/share/ipa/ca-topology.uldif 0.208 sec 2020-06-03T06:36:27Z DEBUG Destroyed connection context.ldap2_140690288788240 2020-06-03T06:36:27Z DEBUG step duration: pki-tomcatd __setup_replication 6.73 sec 2020-06-03T06:36:27Z DEBUG [3/30]: creating ACIs for admin 2020-06-03T06:36:27Z DEBUG Added ACI to read groups to ou=groups,o=ipaca 2020-06-03T06:36:27Z DEBUG step duration: pki-tomcatd add_ipaca_aci 0.02 sec 2020-06-03T06:36:27Z DEBUG [4/30]: creating installation admin user 2020-06-03T06:36:27Z DEBUG Waiting 300 seconds for uid=admin-replica1.ipa.test,ou=people,o=ipaca to appear on ldap://master1.ipa.test:389 2020-06-03T06:36:28Z DEBUG Successfully logged in as uid=admin-replica1.ipa.test,ou=people,o=ipaca 2020-06-03T06:36:28Z DEBUG Waiting up to 300 seconds for replication (ldap://master1.ipa.test:389) cn=Enterprise CA Administrators,ou=groups,o=ipaca (uniqueMember=uid=admin-replica1.ipa.test,ou=people,o=ipaca) 2020-06-03T06:36:28Z DEBUG Entry found [LDAPEntry(ipapython.dn.DN('cn=Enterprise CA Administrators,ou=groups,o=ipaca'), {'uniquemember': [b'uid=admin,ou=People,o=ipaca', b'uid=admin-replica1.ipa.test,ou=people,o=ipaca']})] 2020-06-03T06:36:28Z DEBUG Waiting up to 300 seconds for replication (ldap://master1.ipa.test:389) cn=Enterprise KRA Administrators,ou=groups,o=ipaca (uniqueMember=uid=admin-replica1.ipa.test,ou=people,o=ipaca) 2020-06-03T06:36:28Z DEBUG Entry found [LDAPEntry(ipapython.dn.DN('cn=Enterprise KRA Administrators,ou=groups,o=ipaca'), {'uniquemember': [b'uid=admin,ou=People,o=ipaca', b'uid=admin-replica1.ipa.test,ou=people,o=ipaca']})] 2020-06-03T06:36:28Z DEBUG Waiting up to 300 seconds for replication (ldap://master1.ipa.test:389) cn=Security Domain Administrators,ou=groups,o=ipaca (uniqueMember=uid=admin-replica1.ipa.test,ou=people,o=ipaca) 2020-06-03T06:36:28Z DEBUG Entry found [LDAPEntry(ipapython.dn.DN('cn=Security Domain Administrators,ou=groups,o=ipaca'), {'uniquemember': [b'uid=admin,ou=People,o=ipaca', b'uid=admin-replica1.ipa.test,ou=people,o=ipaca']})] 2020-06-03T06:36:28Z DEBUG step duration: pki-tomcatd setup_admin 1.10 sec 2020-06-03T06:36:28Z DEBUG [5/30]: configuring certificate server instance 2020-06-03T06:36:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:28Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:28Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:28Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:36:28Z DEBUG Contents of pkispawn configuration file (/tmp/.private/root/tmpay_xii95): [CA] pki_admin_cert_file = /root/.dogtag/pki-tomcat/ca_admin.cert pki_admin_cert_request_type = pkcs10 pki_admin_dualkey = False pki_admin_email = root@localhost pki_admin_name = admin-replica1.ipa.test pki_admin_nickname = ipa-ca-agent pki_admin_password = XXXXXXXX pki_admin_subject_dn = cn=ipa-ca-agent,O=IPA.TEST pki_admin_uid = admin-replica1.ipa.test pki_audit_group = pkiaudit pki_audit_signing_key_algorithm = SHA256withRSA pki_audit_signing_key_size = 2048 pki_audit_signing_key_type = rsa pki_audit_signing_nickname = auditSigningCert cert-pki-ca pki_audit_signing_signing_algorithm = SHA256withRSA pki_audit_signing_subject_dn = cn=CA Audit,O=IPA.TEST pki_audit_signing_token = internal pki_backup_keys = True pki_backup_password = XXXXXXXX pki_ca_hostname = master1.ipa.test pki_ca_port = 443 pki_ca_signing_cert_path = /etc/pki/pki-tomcat/external_ca.cert pki_ca_signing_csr_path = /root/ipa.csr pki_ca_signing_key_algorithm = SHA256withRSA pki_ca_signing_key_size = 3072 pki_ca_signing_key_type = rsa pki_ca_signing_nickname = caSigningCert cert-pki-ca pki_ca_signing_record_create = True pki_ca_signing_serial_number = 1 pki_ca_signing_signing_algorithm = SHA256withRSA pki_ca_signing_subject_dn = CN=Certificate Authority,O=IPA.TEST pki_ca_signing_token = internal pki_ca_starting_crl_number = 0 pki_cert_chain_nickname = caSigningCert External CA pki_cert_chain_path = /etc/pki/pki-tomcat/external_ca_chain.cert pki_client_admin_cert_p12 = /root/ca-agent.p12 pki_client_database_password = pki_client_database_purge = True pki_client_dir = /root/.dogtag/pki-tomcat pki_client_pkcs12_password = XXXXXXXX pki_clone = True pki_clone_pkcs12_password = XXXXXXXX pki_clone_pkcs12_path = /tmp/ca.p12 pki_clone_reindex_data = True pki_clone_replicate_schema = False pki_clone_replication_clone_port = 389 pki_clone_replication_master_port = 389 pki_clone_replication_security = TLS pki_clone_setup_replication = False pki_clone_uri = https://master1.ipa.test:443 pki_configuration_path = /etc/pki pki_default_ocsp_uri = http://ipa-ca.ipa.test/ca/ocsp pki_dns_domainname = ipa.test pki_ds_base_dn = o=ipaca pki_ds_bind_dn = cn=Directory Manager pki_ds_create_new_db = False pki_ds_database = ipaca pki_ds_hostname = replica1.ipa.test pki_ds_ldap_port = 389 pki_ds_ldaps_port = 636 pki_ds_password = XXXXXXXX pki_ds_remove_data = True pki_ds_secure_connection = True pki_ds_secure_connection_ca_nickname = Directory Server CA certificate pki_ds_secure_connection_ca_pem_file = /etc/ipa/ca.crt pki_enable_proxy = True pki_existing = False pki_external = False pki_external_pkcs12_password = pki_external_pkcs12_path = pki_external_step_two = False pki_group = pkiuser pki_hostname = replica1.ipa.test pki_hsm_enable = False pki_hsm_libfile = pki_hsm_modulename = pki_import_admin_cert = False pki_instance_configuration_path = /etc/pki/pki-tomcat pki_instance_name = pki-tomcat pki_issuing_ca = https://replica1.ipa.test:443 pki_issuing_ca_hostname = master1.ipa.test pki_issuing_ca_https_port = 443 pki_issuing_ca_uri = https://replica1.ipa.test:443 pki_master_crl_enable = True pki_ocsp_signing_key_algorithm = SHA256withRSA pki_ocsp_signing_key_size = 2048 pki_ocsp_signing_key_type = rsa pki_ocsp_signing_nickname = ocspSigningCert cert-pki-ca pki_ocsp_signing_signing_algorithm = SHA256withRSA pki_ocsp_signing_subject_dn = cn=OCSP Subsystem,O=IPA.TEST pki_ocsp_signing_token = internal pki_pkcs12_password = pki_pkcs12_path = pki_profiles_in_ldap = True pki_random_serial_numbers_enable = False pki_replica_number_range_end = 100 pki_replica_number_range_start = 1 pki_replication_password = pki_request_number_range_end = 10000000 pki_request_number_range_start = 1 pki_restart_configured_instance = False pki_san_for_server_cert = pki_san_inject = False pki_security_domain_hostname = master1.ipa.test pki_security_domain_https_port = 443 pki_security_domain_name = IPA pki_security_domain_password = XXXXXXXX pki_security_domain_user = admin-replica1.ipa.test pki_self_signed_token = internal pki_serial_number_range_end = 10000000 pki_serial_number_range_start = 1 pki_server_database_password = XXXXXXXX pki_share_db = False pki_skip_configuration = False pki_skip_ds_verify = False pki_skip_installation = False pki_skip_sd_verify = False pki_ssl_server_token = internal pki_sslserver_key_algorithm = SHA256withRSA pki_sslserver_key_size = 2048 pki_sslserver_key_type = rsa pki_sslserver_nickname = Server-Cert cert-pki-ca pki_sslserver_subject_dn = cn=replica1.ipa.test,O=IPA.TEST pki_sslserver_token = internal pki_status_request_timeout = 15 pki_subordinate = False pki_subordinate_create_new_security_domain = False pki_subsystem = CA pki_subsystem_key_algorithm = SHA256withRSA pki_subsystem_key_size = 2048 pki_subsystem_key_type = rsa pki_subsystem_nickname = subsystemCert cert-pki-ca pki_subsystem_subject_dn = cn=CA Subsystem,O=IPA.TEST pki_subsystem_token = internal pki_subsystem_type = ca pki_theme_enable = True pki_theme_server_dir = /usr/share/pki/common-ui pki_token_name = internal pki_user = pkiuser 2020-06-03T06:36:28Z DEBUG Starting external process 2020-06-03T06:36:28Z DEBUG args=['/usr/sbin/pkispawn', '-s', 'CA', '-f', '/tmp/.private/root/tmpay_xii95'] 2020-06-03T06:38:12Z DEBUG Process finished, return code=0 2020-06-03T06:38:12Z DEBUG stdout=--------------- 4 entries found --------------- Certificate ID: b3de6015821f821d8d0b7b5a7f07edec371f419d Serial Number: 0x1 Friendly Name: caSigningCert cert-pki-ca Subject DN: CN=Certificate Authority,O=IPA.TEST Issuer DN: CN=Certificate Authority,O=IPA.TEST Trust Flags: CTu,Cu,Cu Has Key: true Key ID: 65b5d4f85c7f8ab7001e5a762b5f696010c5cc6a Certificate ID: ed6ec49e0244fc94921554f25992b19ce4152c89 Serial Number: 0x2 Friendly Name: ocspSigningCert cert-pki-ca Subject DN: CN=OCSP Subsystem,O=IPA.TEST Issuer DN: CN=Certificate Authority,O=IPA.TEST Trust Flags: u,u,u Has Key: true Key ID: 2c4a492a029abb13093855637fddd9e5d6c6b64b Certificate ID: 57f2b72b1c1bd85e428fe2bc9daac756de7fd0fb Serial Number: 0x5 Friendly Name: auditSigningCert cert-pki-ca Subject DN: CN=CA Audit,O=IPA.TEST Issuer DN: CN=Certificate Authority,O=IPA.TEST Trust Flags: u,u,u Has Key: true Key ID: 1fb50167b2a4859a7001faf2c417d7b7856de7dd Certificate ID: a40647e57117b04e7da36fc2a591e984ada02af6 Serial Number: 0x4 Friendly Name: subsystemCert cert-pki-ca Subject DN: CN=CA Subsystem,O=IPA.TEST Issuer DN: CN=Certificate Authority,O=IPA.TEST Trust Flags: u,u,u Has Key: true Key ID: c58407a3fbb4b089f3afeec6aefbfd4f6bd263c8 --------------- Import complete --------------- Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI caSigningCert cert-pki-ca CTu,Cu,Cu ocspSigningCert cert-pki-ca u,u,u auditSigningCert cert-pki-ca u,u,Pu subsystemCert cert-pki-ca u,u,u Installation log: /var/log/pki/pki-ca-spawn.20200603063629.log Loading deployment configuration from /tmp/.private/root/tmpay_xii95. WARNING: The 'pki_ssl_server_token' in [CA] has been deprecated. Use 'pki_sslserver_token' instead. Installing CA into /var/lib/pki/pki-tomcat. Importing certificates from /tmp/ca.p12: Imported certificates into /etc/pki/pki-tomcat/alias: ========================================================================== INSTALLATION SUMMARY ========================================================================== Administrator's username: admin-replica1.ipa.test This CA subsystem of the 'pki-tomcat' instance is a clone. To check the status of the subsystem: systemctl status pki-tomcatd@pki-tomcat.service To restart the subsystem: systemctl restart pki-tomcatd@pki-tomcat.service The URL for the subsystem is: https://replica1.ipa.test:8443/ca PKI instances will be enabled upon system boot ========================================================================== 2020-06-03T06:38:12Z DEBUG stderr=Notice: Trust flag u is set automatically if the private key is present. 2020-06-03T06:38:12Z DEBUG completed creating ca instance 2020-06-03T06:38:12Z DEBUG step duration: pki-tomcatd __spawn_instance 103.37 sec 2020-06-03T06:38:12Z DEBUG [6/30]: Add ipa-pki-wait-running 2020-06-03T06:38:12Z DEBUG Starting external process 2020-06-03T06:38:12Z DEBUG args=['/sbin/systemctl', '--system', 'daemon-reload'] 2020-06-03T06:38:12Z DEBUG Process finished, return code=0 2020-06-03T06:38:12Z DEBUG stdout= 2020-06-03T06:38:12Z DEBUG stderr= 2020-06-03T06:38:12Z DEBUG step duration: pki-tomcatd add_ipa_wait 0.17 sec 2020-06-03T06:38:12Z DEBUG [7/30]: secure AJP connector 2020-06-03T06:38:12Z DEBUG Starting external process 2020-06-03T06:38:12Z DEBUG args=['/usr/sbin/tomcat', 'version'] 2020-06-03T06:38:12Z DEBUG Process finished, return code=0 2020-06-03T06:38:12Z DEBUG stdout=Server version: Apache Tomcat/9.0.13 Server built: Mar 26 2019 06:37:22 UTC Server number: 9.0.13.0 OS Name: Linux OS Version: 5.3.0-1020-azure Architecture: amd64 JVM Version: 1.8.0_212-b04 JVM Vendor: Oracle Corporation 2020-06-03T06:38:12Z DEBUG stderr= 2020-06-03T06:38:12Z DEBUG step duration: pki-tomcatd secure_ajp_connector 0.09 sec 2020-06-03T06:38:12Z DEBUG [8/30]: reindex attributes 2020-06-03T06:38:12Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:38:12Z DEBUG Creating ipaca reindex task cn=indextask_ipaca_1591166292,cn=index,cn=tasks,cn=config 2020-06-03T06:38:12Z DEBUG Waiting for task... 2020-06-03T06:38:13Z DEBUG Task cn=indextask_ipaca_1591166292,cn=index,cn=tasks,cn=config has finished with exit code 0 2020-06-03T06:38:13Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:38:13Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:38:13Z DEBUG step duration: pki-tomcatd reindex_task 1.02 sec 2020-06-03T06:38:13Z DEBUG [9/30]: exporting Dogtag certificate store pin 2020-06-03T06:38:13Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:38:13Z DEBUG step duration: pki-tomcatd create_certstore_passwdfile 0.00 sec 2020-06-03T06:38:13Z DEBUG [10/30]: stopping certificate server instance to update CS.cfg 2020-06-03T06:38:13Z DEBUG Starting external process 2020-06-03T06:38:13Z DEBUG args=['/sbin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:14Z DEBUG Process finished, return code=0 2020-06-03T06:38:14Z DEBUG stdout= 2020-06-03T06:38:14Z DEBUG stderr= 2020-06-03T06:38:14Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2020-06-03T06:38:14Z DEBUG step duration: pki-tomcatd stop_instance 0.67 sec 2020-06-03T06:38:14Z DEBUG [11/30]: backing up CS.cfg 2020-06-03T06:38:14Z DEBUG Starting external process 2020-06-03T06:38:14Z DEBUG args=['/sbin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:14Z DEBUG Process finished, return code=3 2020-06-03T06:38:14Z DEBUG stdout=inactive 2020-06-03T06:38:14Z DEBUG stderr= 2020-06-03T06:38:14Z DEBUG step duration: pki-tomcatd safe_backup_config 0.01 sec 2020-06-03T06:38:14Z DEBUG [12/30]: disabling nonces 2020-06-03T06:38:14Z DEBUG step duration: pki-tomcatd __disable_nonce 0.00 sec 2020-06-03T06:38:14Z DEBUG [13/30]: set up CRL publishing 2020-06-03T06:38:14Z DEBUG Starting external process 2020-06-03T06:38:14Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:38:14Z DEBUG Process finished, return code=1 2020-06-03T06:38:14Z DEBUG stdout= 2020-06-03T06:38:14Z DEBUG stderr= 2020-06-03T06:38:14Z DEBUG step duration: pki-tomcatd __enable_crl_publish 0.04 sec 2020-06-03T06:38:14Z DEBUG [14/30]: enable PKIX certificate path discovery and validation 2020-06-03T06:38:14Z DEBUG step duration: pki-tomcatd enable_pkix 0.00 sec 2020-06-03T06:38:14Z DEBUG [15/30]: destroying installation admin user 2020-06-03T06:38:14Z DEBUG step duration: pki-tomcatd teardown_admin 0.04 sec 2020-06-03T06:38:14Z DEBUG [16/30]: starting certificate server instance 2020-06-03T06:38:14Z DEBUG Starting external process 2020-06-03T06:38:14Z DEBUG args=['/sbin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:23Z DEBUG Process finished, return code=0 2020-06-03T06:38:23Z DEBUG stdout= 2020-06-03T06:38:23Z DEBUG stderr= 2020-06-03T06:38:23Z DEBUG Starting external process 2020-06-03T06:38:23Z DEBUG args=['/sbin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:23Z DEBUG Process finished, return code=0 2020-06-03T06:38:23Z DEBUG stdout=active 2020-06-03T06:38:23Z DEBUG stderr= 2020-06-03T06:38:23Z DEBUG wait_for_open_ports: localhost [8090, 8443] timeout 120 2020-06-03T06:38:23Z DEBUG waiting for port: 8090 2020-06-03T06:38:23Z DEBUG SUCCESS: port: 8090 2020-06-03T06:38:23Z DEBUG waiting for port: 8443 2020-06-03T06:38:23Z DEBUG SUCCESS: port: 8443 2020-06-03T06:38:23Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2020-06-03T06:38:23Z DEBUG step duration: pki-tomcatd start_instance 9.10 sec 2020-06-03T06:38:23Z DEBUG [17/30]: Finalize replication settings 2020-06-03T06:38:23Z DEBUG step duration: pki-tomcatd finalize_replica_config 0.06 sec 2020-06-03T06:38:23Z DEBUG [18/30]: configure certmonger for renewals 2020-06-03T06:38:23Z DEBUG Starting external process 2020-06-03T06:38:23Z DEBUG args=['/sbin/systemctl', 'enable', 'certmonger.service'] 2020-06-03T06:38:23Z DEBUG Process finished, return code=0 2020-06-03T06:38:23Z DEBUG stdout= 2020-06-03T06:38:23Z DEBUG stderr= 2020-06-03T06:38:23Z DEBUG Starting external process 2020-06-03T06:38:23Z DEBUG args=['/sbin/systemctl', 'is-active', 'dbus.service'] 2020-06-03T06:38:23Z DEBUG Process finished, return code=0 2020-06-03T06:38:23Z DEBUG stdout=active 2020-06-03T06:38:23Z DEBUG stderr= 2020-06-03T06:38:23Z DEBUG Starting external process 2020-06-03T06:38:23Z DEBUG args=['/sbin/systemctl', 'start', 'certmonger.service'] 2020-06-03T06:38:23Z DEBUG Process finished, return code=0 2020-06-03T06:38:23Z DEBUG stdout= 2020-06-03T06:38:23Z DEBUG stderr= 2020-06-03T06:38:23Z DEBUG Starting external process 2020-06-03T06:38:23Z DEBUG args=['/sbin/systemctl', 'is-active', 'certmonger.service'] 2020-06-03T06:38:23Z DEBUG Process finished, return code=0 2020-06-03T06:38:23Z DEBUG stdout=active 2020-06-03T06:38:23Z DEBUG stderr= 2020-06-03T06:38:23Z DEBUG Start of certmonger.service complete 2020-06-03T06:38:24Z DEBUG step duration: pki-tomcatd configure_certmonger_renewal_helpers 0.66 sec 2020-06-03T06:38:24Z DEBUG [19/30]: Importing RA key 2020-06-03T06:38:24Z DEBUG Waiting up to 300 seconds to see our keys appear on host ldap://master1.ipa.test 2020-06-03T06:38:24Z DEBUG Starting new HTTPS connection (1): master1.ipa.test:443 2020-06-03T06:38:25Z DEBUG https://master1.ipa.test:443 "GET /ipa/keys/ra/ipaCert?type=kem&value=eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZDQkMtSFM1MTIiLCJraWQiOm51bGx9.mm_quxTW_TUOEaHFPk9LT6_aVodUqKfeXoHxXOcPWALyfBmaEjq60O9mfZRh9VyaN6kXbHiZEdAbRbdof5gPeaQP-jZ8HY7xC8WYVTzADsJ73KaptOtc5zSvUpdHIXUW9X0VzolbTOqh6PbY_qyv1xP62OYlysNpjpD-DflUCNzxZkulThx3ztcogH57iThVP6AGut4e6treg7TJEoTRr_OsvHMXuLb86EMfh9-u5TKxEorE2Sft7dztcK02RfheKgxDjELVBL6FxECt5WRe3gr8XdZSMT98N3A3hO0DaQvplro9l2hCkLTunF0Ws5cxkWvc2qlSzbPBN1A-vseNRg.OnC1xOFc9XWeMI8Oz8Varw.dewYtNupApv5OFOOEV7pe-ZEBkJF0pOfW3D7orMgZAzHXnFV8FZdSj-hjLKPw_iTVWHSzZ23GiCGrrwcPaPoqJZSvdxstngbYeFaFlKrOvF6XL7-wfFyfwlQl8MJCh1PmThxhYjpVXllrqUJySFPlSMqEEGd8EoTzJUpoukfyfLJ2oUiw4G_3DQC3zoy1CjyUkdQNYgyM-M8mr1T75E2B6ShuKG9qnq6QEM-sQYJvJO8CllyrCiRfoIeBoSH9HIzBSzgpsPGpKtNG5oF9D53Iw-O5xH2jIAngAqAk12BmsoogG80DpSuJ8eWjR7xJT7xTMzapTD_c8Y7r4aqYoxg2TPw6kQA-kemJ90Utt-XiUn6Wz7WrtBSzIudgPX5iX74uKCxh0ldPkAInjgfy0QqkffeTV0CqzBOeT2DrhXijJt_VYRdiZ3hjZE8LpE-zNsiC3aogZeveD14JqM5SKDP72suHmZj-h2AO4JfPIuFtEAWPUj7TvR7qHEh7TpKc13fwu3EaZn4RxUyiu11hDBa4fSTeZWsBuUHOwLwkwbIb0t7zF6PP76EyN8xPNyKoS4MsbF7tqSqxiZtR7eMbbWHxgIYyxVjp6qp-f3Zvtvl5LwY7SYwNWAf4oRjl6T5NDU6.h22szVJrDxzm9GAJftH2IBMGVhbHN9yfN56XKEn5KYw HTTP/1.1" 200 5682 2020-06-03T06:38:25Z DEBUG Starting external process 2020-06-03T06:38:25Z DEBUG args=['/usr/libexec/ipa/custodia/ipa-custodia-ra-agent', '--import', '-'] 2020-06-03T06:38:28Z DEBUG Process finished, return code=0 2020-06-03T06:38:28Z DEBUG stdout= 2020-06-03T06:38:28Z DEBUG stderr= 2020-06-03T06:38:28Z DEBUG Starting external process 2020-06-03T06:38:28Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:38:28Z DEBUG Process finished, return code=1 2020-06-03T06:38:28Z DEBUG stdout= 2020-06-03T06:38:28Z DEBUG stderr= 2020-06-03T06:38:28Z DEBUG Starting external process 2020-06-03T06:38:28Z DEBUG args=['/usr/sbin/selinuxenabled'] 2020-06-03T06:38:28Z DEBUG Process finished, return code=1 2020-06-03T06:38:28Z DEBUG stdout= 2020-06-03T06:38:28Z DEBUG stderr= 2020-06-03T06:38:28Z DEBUG step duration: pki-tomcatd __import_ra_key 4.45 sec 2020-06-03T06:38:28Z DEBUG [20/30]: setting audit signing renewal to 2 years 2020-06-03T06:38:28Z DEBUG caSignedLogCert.cfg profile validity range is 720 2020-06-03T06:38:28Z DEBUG step duration: pki-tomcatd set_audit_renewal 0.00 sec 2020-06-03T06:38:28Z DEBUG [21/30]: restarting certificate server 2020-06-03T06:38:28Z DEBUG Starting external process 2020-06-03T06:38:28Z DEBUG args=['/sbin/systemctl', 'restart', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:41Z DEBUG Process finished, return code=0 2020-06-03T06:38:41Z DEBUG stdout= 2020-06-03T06:38:41Z DEBUG stderr= 2020-06-03T06:38:41Z DEBUG Starting external process 2020-06-03T06:38:41Z DEBUG args=['/sbin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:41Z DEBUG Process finished, return code=0 2020-06-03T06:38:41Z DEBUG stdout=active 2020-06-03T06:38:41Z DEBUG stderr= 2020-06-03T06:38:41Z DEBUG wait_for_open_ports: localhost [8090, 8443] timeout 120 2020-06-03T06:38:41Z DEBUG waiting for port: 8090 2020-06-03T06:38:41Z DEBUG SUCCESS: port: 8090 2020-06-03T06:38:41Z DEBUG waiting for port: 8443 2020-06-03T06:38:41Z DEBUG SUCCESS: port: 8443 2020-06-03T06:38:41Z DEBUG Restart of pki-tomcatd@pki-tomcat.service complete 2020-06-03T06:38:41Z DEBUG step duration: pki-tomcatd restart_instance 13.00 sec 2020-06-03T06:38:41Z DEBUG [22/30]: authorizing RA to modify profiles 2020-06-03T06:38:41Z DEBUG step duration: pki-tomcatd configure_profiles_acl 0.01 sec 2020-06-03T06:38:41Z DEBUG [23/30]: authorizing RA to manage lightweight CAs 2020-06-03T06:38:41Z DEBUG step duration: pki-tomcatd configure_lightweight_ca_acls 0.00 sec 2020-06-03T06:38:41Z DEBUG [24/30]: Ensure lightweight CAs container exists 2020-06-03T06:38:41Z DEBUG Created connection context.ldap2_140690267426384 2020-06-03T06:38:41Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:38:41Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:38:41Z DEBUG Destroyed connection context.ldap2_140690267426384 2020-06-03T06:38:41Z DEBUG step duration: pki-tomcatd ensure_lightweight_cas_container 0.20 sec 2020-06-03T06:38:41Z DEBUG [25/30]: configure certificate renewals 2020-06-03T06:38:41Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:38:42Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:38:42Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:38:43Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:38:44Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:38:46Z DEBUG step duration: pki-tomcatd configure_renewal 4.21 sec 2020-06-03T06:38:46Z DEBUG [26/30]: Configure HTTP to proxy connections 2020-06-03T06:38:46Z DEBUG step duration: pki-tomcatd http_proxy 0.00 sec 2020-06-03T06:38:46Z DEBUG [27/30]: restarting certificate server 2020-06-03T06:38:46Z DEBUG Starting external process 2020-06-03T06:38:46Z DEBUG args=['/sbin/systemctl', 'restart', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:55Z DEBUG Process finished, return code=0 2020-06-03T06:38:55Z DEBUG stdout= 2020-06-03T06:38:55Z DEBUG stderr= 2020-06-03T06:38:55Z DEBUG Starting external process 2020-06-03T06:38:55Z DEBUG args=['/sbin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:55Z DEBUG Process finished, return code=0 2020-06-03T06:38:55Z DEBUG stdout=active 2020-06-03T06:38:55Z DEBUG stderr= 2020-06-03T06:38:55Z DEBUG wait_for_open_ports: localhost [8090, 8443] timeout 120 2020-06-03T06:38:55Z DEBUG waiting for port: 8090 2020-06-03T06:38:55Z DEBUG SUCCESS: port: 8090 2020-06-03T06:38:55Z DEBUG waiting for port: 8443 2020-06-03T06:38:55Z DEBUG SUCCESS: port: 8443 2020-06-03T06:38:55Z DEBUG Restart of pki-tomcatd@pki-tomcat.service complete 2020-06-03T06:38:55Z DEBUG step duration: pki-tomcatd restart_instance 9.94 sec 2020-06-03T06:38:55Z DEBUG [28/30]: updating IPA configuration 2020-06-03T06:38:55Z DEBUG step duration: pki-tomcatd update_ipa_conf 0.00 sec 2020-06-03T06:38:55Z DEBUG [29/30]: enabling CA instance 2020-06-03T06:38:55Z DEBUG Starting external process 2020-06-03T06:38:55Z DEBUG args=['/sbin/systemctl', 'disable', 'pki-tomcatd.target'] 2020-06-03T06:38:56Z DEBUG Process finished, return code=0 2020-06-03T06:38:56Z DEBUG stdout= 2020-06-03T06:38:56Z DEBUG stderr= 2020-06-03T06:38:56Z DEBUG step duration: pki-tomcatd __enable_instance 0.15 sec 2020-06-03T06:38:56Z DEBUG [30/30]: configuring certmonger renewal for lightweight CAs 2020-06-03T06:38:56Z DEBUG step duration: pki-tomcatd add_lightweight_ca_tracking_requests 0.00 sec 2020-06-03T06:38:56Z DEBUG Done configuring certificate server (pki-tomcatd). 2020-06-03T06:38:56Z DEBUG service duration: pki-tomcatd 155.14 sec 2020-06-03T06:38:56Z DEBUG Removing /root/.dogtag/pki-tomcat/ca 2020-06-03T06:38:56Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:38:56Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:38:56Z DEBUG Starting external process 2020-06-03T06:38:56Z DEBUG args=['/sbin/systemctl', 'stop', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:57Z DEBUG Process finished, return code=0 2020-06-03T06:38:57Z DEBUG stdout= 2020-06-03T06:38:57Z DEBUG stderr= 2020-06-03T06:38:57Z DEBUG Stop of pki-tomcatd@pki-tomcat.service complete 2020-06-03T06:38:57Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:38:57Z DEBUG Ensuring that service pki-tomcatd@pki-tomcat is not running while the next set of commands is being executed. 2020-06-03T06:38:57Z DEBUG Starting external process 2020-06-03T06:38:57Z DEBUG args=['/sbin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:38:57Z DEBUG Process finished, return code=3 2020-06-03T06:38:57Z DEBUG stdout=inactive 2020-06-03T06:38:57Z DEBUG stderr= 2020-06-03T06:38:57Z DEBUG Service pki-tomcatd@pki-tomcat is not running, continue. 2020-06-03T06:38:57Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:38:57Z DEBUG Set up lightweight CA key retrieval 2020-06-03T06:38:57Z DEBUG Creating principal 2020-06-03T06:38:57Z DEBUG Starting external process 2020-06-03T06:38:57Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'addprinc -randkey dogtag/replica1.ipa.test@IPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2020-06-03T06:38:57Z DEBUG Process finished, return code=0 2020-06-03T06:38:57Z DEBUG stdout=Authenticating as principal host/admin@IPA.TEST with password. Principal "dogtag/replica1.ipa.test@IPA.TEST" created. 2020-06-03T06:38:57Z DEBUG stderr=WARNING: no policy specified for dogtag/replica1.ipa.test@IPA.TEST; defaulting to no policy 2020-06-03T06:38:57Z DEBUG Retrieving keytab 2020-06-03T06:38:57Z DEBUG Starting external process 2020-06-03T06:38:57Z DEBUG args=['/usr/sbin/kadmin.local', '-q', 'ktadd -k /etc/pki/pki-tomcat/dogtag.keytab dogtag/replica1.ipa.test@IPA.TEST', '-x', 'ipa-setup-override-restrictions'] 2020-06-03T06:38:57Z DEBUG Process finished, return code=0 2020-06-03T06:38:57Z DEBUG stdout=Authenticating as principal host/admin@IPA.TEST with password. Entry for principal dogtag/replica1.ipa.test@IPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/replica1.ipa.test@IPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha1-96 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/replica1.ipa.test@IPA.TEST with kvno 2, encryption type aes128-cts-hmac-sha256-128 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/replica1.ipa.test@IPA.TEST with kvno 2, encryption type aes256-cts-hmac-sha384-192 added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/replica1.ipa.test@IPA.TEST with kvno 2, encryption type camellia128-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. Entry for principal dogtag/replica1.ipa.test@IPA.TEST with kvno 2, encryption type camellia256-cts-cmac added to keytab WRFILE:/etc/pki/pki-tomcat/dogtag.keytab. 2020-06-03T06:38:57Z DEBUG stderr= 2020-06-03T06:38:57Z DEBUG Creating Custodia keys 2020-06-03T06:38:57Z DEBUG Created connection context.ldap2_140690289851024 2020-06-03T06:38:57Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:38:57Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:38:57Z DEBUG Destroyed connection context.ldap2_140690289851024 2020-06-03T06:38:57Z DEBUG Created connection context.ldap2_140690265840896 2020-06-03T06:38:57Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:38:57Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:38:57Z DEBUG Destroyed connection context.ldap2_140690265840896 2020-06-03T06:38:58Z DEBUG Configuring key retriever 2020-06-03T06:38:58Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:38:58Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:38:58Z DEBUG Destroyed connection context.ldap2_140690310172784 2020-06-03T06:38:58Z DEBUG Starting external process 2020-06-03T06:38:58Z DEBUG args=['/sbin/systemctl', 'restart', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:39:05Z DEBUG Process finished, return code=0 2020-06-03T06:39:05Z DEBUG stdout= 2020-06-03T06:39:05Z DEBUG stderr= 2020-06-03T06:39:05Z DEBUG Restart of dirsrv@IPA-TEST.service complete 2020-06-03T06:39:05Z DEBUG Created connection context.ldap2_140690310172784 2020-06-03T06:39:05Z DEBUG Starting external process 2020-06-03T06:39:05Z DEBUG args=['/sbin/systemctl', 'start', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:39:15Z DEBUG Process finished, return code=0 2020-06-03T06:39:15Z DEBUG stdout= 2020-06-03T06:39:15Z DEBUG stderr= 2020-06-03T06:39:15Z DEBUG Starting external process 2020-06-03T06:39:15Z DEBUG args=['/sbin/systemctl', 'is-active', 'pki-tomcatd@pki-tomcat.service'] 2020-06-03T06:39:15Z DEBUG Process finished, return code=0 2020-06-03T06:39:15Z DEBUG stdout=active 2020-06-03T06:39:15Z DEBUG stderr= 2020-06-03T06:39:15Z DEBUG wait_for_open_ports: localhost [8090, 8443] timeout 120 2020-06-03T06:39:15Z DEBUG waiting for port: 8090 2020-06-03T06:39:15Z DEBUG SUCCESS: port: 8090 2020-06-03T06:39:15Z DEBUG waiting for port: 8443 2020-06-03T06:39:15Z DEBUG SUCCESS: port: 8443 2020-06-03T06:39:15Z DEBUG Start of pki-tomcatd@pki-tomcat.service complete 2020-06-03T06:39:15Z DEBUG Starting external process 2020-06-03T06:39:15Z DEBUG args=['/sbin/systemctl', 'restart', 'httpd2.service'] 2020-06-03T06:39:17Z DEBUG Process finished, return code=0 2020-06-03T06:39:17Z DEBUG stdout= 2020-06-03T06:39:17Z DEBUG stderr= 2020-06-03T06:39:17Z DEBUG Starting external process 2020-06-03T06:39:17Z DEBUG args=['/sbin/systemctl', 'is-active', 'httpd2.service'] 2020-06-03T06:39:17Z DEBUG Process finished, return code=0 2020-06-03T06:39:17Z DEBUG stdout=active 2020-06-03T06:39:17Z DEBUG stderr= 2020-06-03T06:39:17Z DEBUG Restart of httpd2.service complete 2020-06-03T06:39:18Z DEBUG Waiting up to 300 seconds for replication (ldap://master1.ipa.test:389) cn=KDC,cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test (objectclass=*) 2020-06-03T06:39:18Z DEBUG Entry found [LDAPEntry(ipapython.dn.DN('cn=KDC,cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test'), {'objectClass': [b'nsContainer', b'ipaConfigObject', b'top'], 'cn': [b'KDC'], 'ipaConfigString': [b'configuredService', b'startOrder 10', b'kdcProxyEnabled']})] 2020-06-03T06:39:18Z DEBUG Configuring Kerberos KDC (krb5kdc) 2020-06-03T06:39:18Z DEBUG [1/1]: installing X509 Certificate for PKINIT 2020-06-03T06:39:18Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:39:18Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:39:18Z DEBUG certmonger request is in state dbus.String('NEWLY_ADDED_READING_KEYINFO', variant_level=1) 2020-06-03T06:39:23Z DEBUG certmonger request is in state dbus.String('POST_SAVED_CERT', variant_level=1) 2020-06-03T06:39:28Z DEBUG certmonger request is in state dbus.String('MONITORING', variant_level=1) 2020-06-03T06:39:28Z DEBUG Cert request 20200603063918 was successful 2020-06-03T06:39:28Z DEBUG service KDC has all config values set 2020-06-03T06:39:28Z DEBUG step duration: krb5kdc setup_pkinit 10.65 sec 2020-06-03T06:39:28Z DEBUG Done configuring Kerberos KDC (krb5kdc). 2020-06-03T06:39:28Z DEBUG service duration: krb5kdc 10.65 sec 2020-06-03T06:39:28Z DEBUG Starting external process 2020-06-03T06:39:28Z DEBUG args=['/sbin/systemctl', 'restart', 'krb5kdc.service'] 2020-06-03T06:39:28Z DEBUG Process finished, return code=0 2020-06-03T06:39:28Z DEBUG stdout= 2020-06-03T06:39:28Z DEBUG stderr= 2020-06-03T06:39:28Z DEBUG Starting external process 2020-06-03T06:39:28Z DEBUG args=['/sbin/systemctl', 'is-active', 'krb5kdc.service'] 2020-06-03T06:39:28Z DEBUG Process finished, return code=0 2020-06-03T06:39:28Z DEBUG stdout=active 2020-06-03T06:39:28Z DEBUG stderr= 2020-06-03T06:39:28Z DEBUG Restart of krb5kdc.service complete 2020-06-03T06:39:28Z DEBUG Applying LDAP updates 2020-06-03T06:39:28Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:39:28Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:39:28Z DEBUG Starting external process 2020-06-03T06:39:28Z DEBUG args=['/sbin/systemctl', 'is-active', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:39:28Z DEBUG Process finished, return code=0 2020-06-03T06:39:28Z DEBUG stdout=active 2020-06-03T06:39:28Z DEBUG stderr= 2020-06-03T06:39:28Z DEBUG Upgrading IPA:. Estimated time: 1 minute 30 seconds 2020-06-03T06:39:28Z DEBUG [1/10]: stopping directory server 2020-06-03T06:39:28Z DEBUG Destroyed connection context.ldap2_140690310172784 2020-06-03T06:39:28Z DEBUG Starting external process 2020-06-03T06:39:28Z DEBUG args=['/sbin/systemctl', 'stop', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:39:31Z DEBUG Process finished, return code=0 2020-06-03T06:39:31Z DEBUG stdout= 2020-06-03T06:39:31Z DEBUG stderr= 2020-06-03T06:39:31Z DEBUG Stop of dirsrv@IPA-TEST.service complete 2020-06-03T06:39:31Z DEBUG step duration: dirsrv __stop_instance 2.72 sec 2020-06-03T06:39:31Z DEBUG [2/10]: saving configuration 2020-06-03T06:39:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:39:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:39:31Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:39:31Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:39:31Z DEBUG step duration: dirsrv __save_config 0.05 sec 2020-06-03T06:39:31Z DEBUG [3/10]: disabling listeners 2020-06-03T06:39:31Z DEBUG step duration: dirsrv __disable_listeners 0.05 sec 2020-06-03T06:39:31Z DEBUG [4/10]: enabling DS global lock 2020-06-03T06:39:31Z DEBUG step duration: dirsrv __enable_ds_global_write_lock 0.05 sec 2020-06-03T06:39:31Z DEBUG [5/10]: disabling Schema Compat 2020-06-03T06:39:31Z DEBUG step duration: dirsrv __disable_schema_compat 0.02 sec 2020-06-03T06:39:31Z DEBUG [6/10]: starting directory server 2020-06-03T06:39:31Z DEBUG Starting external process 2020-06-03T06:39:31Z DEBUG args=['/sbin/systemctl', 'start', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:39:33Z DEBUG Process finished, return code=0 2020-06-03T06:39:33Z DEBUG stdout= 2020-06-03T06:39:33Z DEBUG stderr= 2020-06-03T06:39:33Z DEBUG Start of dirsrv@IPA-TEST.service complete 2020-06-03T06:39:33Z DEBUG Created connection context.ldap2_140690310172784 2020-06-03T06:39:33Z DEBUG step duration: dirsrv __start 1.79 sec 2020-06-03T06:39:33Z DEBUG [7/10]: upgrading server 2020-06-03T06:39:33Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-03T06:39:33Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-03T06:39:33Z DEBUG skipping plugin module ipaserver.plugins.dogtag: dogtag not selected as RA plugin 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-03T06:39:33Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-03T06:39:33Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-03T06:39:33Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-03T06:39:33Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-03T06:39:33Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-03T06:39:33Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-03T06:39:33Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-03T06:39:34Z DEBUG Created connection context.ldap2_140690288004640 2020-06-03T06:39:34Z DEBUG Destroyed connection context.ldap2_140690288004640 2020-06-03T06:39:34Z DEBUG Created connection context.ldap2_140690288004640 2020-06-03T06:39:34Z DEBUG Parsing update file '/usr/share/ipa/updates/05-pre_upgrade_plugins.update' 2020-06-03T06:39:34Z DEBUG Executing upgrade plugin: update_managed_post_first 2020-06-03T06:39:34Z DEBUG raw: update_managed_post_first 2020-06-03T06:39:34Z DEBUG Executing upgrade plugin: update_replica_attribute_lists 2020-06-03T06:39:34Z DEBUG raw: update_replica_attribute_lists 2020-06-03T06:39:34Z DEBUG Start replication agreement exclude list update task 2020-06-03T06:39:34Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:39:34Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:39:34Z DEBUG Found 1 agreement(s) 2020-06-03T06:39:34Z DEBUG me to master1.ipa.test 2020-06-03T06:39:34Z DEBUG nsDS5ReplicatedAttributeList: No update necessary 2020-06-03T06:39:34Z DEBUG nsDS5ReplicatedAttributeListTotal: No update necessary 2020-06-03T06:39:34Z DEBUG nsds5ReplicaStripAttrs: No update necessary 2020-06-03T06:39:34Z DEBUG Done updating agreements 2020-06-03T06:39:34Z DEBUG Executing upgrade plugin: update_passync_privilege_check 2020-06-03T06:39:34Z DEBUG raw: update_passync_privilege_check 2020-06-03T06:39:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:34Z DEBUG Check if there is existing PassSync privilege 2020-06-03T06:39:34Z DEBUG PassSync privilege found, skip updating PassSync 2020-06-03T06:39:34Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:34Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:34Z DEBUG Executing upgrade plugin: update_referint 2020-06-03T06:39:34Z DEBUG raw: update_referint 2020-06-03T06:39:34Z DEBUG Upgrading referential integrity plugin configuration 2020-06-03T06:39:34Z DEBUG Initial value: LDAPEntry(ipapython.dn.DN('cn=referential integrity postoperation,cn=plugins,cn=config'), {'cn': [b'referential integrity postoperation'], 'nsslapd-plugin-depends-on-type': [b'database'], 'nsslapd-pluginDescription': [b'referential integrity plugin'], 'nsslapd-pluginEnabled': [b'on'], 'nsslapd-pluginId': [b'referint'], 'nsslapd-pluginInitfunc': [b'referint_postop_init'], 'nsslapd-pluginPath': [b'libreferint-plugin'], 'nsslapd-pluginType': [b'betxnpostoperation'], 'nsslapd-pluginVendor': [b'389 Project'], 'nsslapd-pluginVersion': [b'1.4.1.18'], 'nsslapd-pluginprecedence': [b'40'], 'objectClass': [b'top', b'nsSlapdPlugin', b'extensibleObject'], 'referint-logfile': [b'/var/log/dirsrv/slapd-IPA-TEST/referint'], 'referint-membership-attr': [b'member', b'uniquemember', b'owner', b'seeAlso'], 'referint-update-delay': [b'0']}) 2020-06-03T06:39:34Z DEBUG Plugin already uses new style, skipping 2020-06-03T06:39:34Z DEBUG Executing upgrade plugin: update_uniqueness_plugins_to_new_syntax 2020-06-03T06:39:34Z DEBUG raw: update_uniqueness_plugins_to_new_syntax 2020-06-03T06:39:34Z DEBUG No uniqueness plugin entries with old style configuration found 2020-06-03T06:39:34Z DEBUG LDAP update duration: /usr/share/ipa/updates/05-pre_upgrade_plugins.update 0.205 sec 2020-06-03T06:39:34Z DEBUG Parsing update file '/usr/share/ipa/updates/10-config.update' 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG only: set nsslapd-ssl-check-hostname to 'on', current value ['on'] 2020-06-03T06:39:34Z DEBUG only: updated value ['on'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG [] 2020-06-03T06:39:34Z DEBUG Updated 0 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG Kerberos Principal Name 2020-06-03T06:39:34Z DEBUG ipamodrdnfilter: 2020-06-03T06:39:34Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2020-06-03T06:39:34Z DEBUG ipamodrdnscope: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG ipamodrdnsourceattr: 2020-06-03T06:39:34Z DEBUG uid 2020-06-03T06:39:34Z DEBUG ipamodrdnsuffix: 2020-06-03T06:39:34Z DEBUG @IPA.TEST 2020-06-03T06:39:34Z DEBUG ipamodrdntargetattr: 2020-06-03T06:39:34Z DEBUG krbPrincipalName 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG remove: '60' from nsslapd-pluginPrecedence, current value [] 2020-06-03T06:39:34Z DEBUG remove: '60' not in nsslapd-pluginPrecedence 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=Kerberos Principal Name,cn=IPA MODRDN,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG Kerberos Principal Name 2020-06-03T06:39:34Z DEBUG ipamodrdnfilter: 2020-06-03T06:39:34Z DEBUG (&(objectclass=posixaccount)(objectclass=krbPrincipalAux)) 2020-06-03T06:39:34Z DEBUG ipamodrdnscope: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG ipamodrdnsourceattr: 2020-06-03T06:39:34Z DEBUG uid 2020-06-03T06:39:34Z DEBUG ipamodrdnsuffix: 2020-06-03T06:39:34Z DEBUG @IPA.TEST 2020-06-03T06:39:34Z DEBUG ipamodrdntargetattr: 2020-06-03T06:39:34Z DEBUG krbPrincipalName 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG [] 2020-06-03T06:39:34Z DEBUG Updated 0 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG IPA MODRDN 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:34Z DEBUG database 2020-06-03T06:39:34Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:34Z DEBUG IPA MODRDN plugin 2020-06-03T06:39:34Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:34Z DEBUG IPA MODRDN 2020-06-03T06:39:34Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:34Z DEBUG ipamodrdn_init 2020-06-03T06:39:34Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:34Z DEBUG libipa_modrdn 2020-06-03T06:39:34Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:34Z DEBUG betxnpostoperation 2020-06-03T06:39:34Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:34Z DEBUG Red Hat, Inc. 2020-06-03T06:39:34Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:34Z DEBUG 1.0 2020-06-03T06:39:34Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG nsSlapdPlugin 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value ['60'] 2020-06-03T06:39:34Z DEBUG only: updated value ['60'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG IPA MODRDN 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:34Z DEBUG database 2020-06-03T06:39:34Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:34Z DEBUG IPA MODRDN plugin 2020-06-03T06:39:34Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:34Z DEBUG IPA MODRDN 2020-06-03T06:39:34Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:34Z DEBUG ipamodrdn_init 2020-06-03T06:39:34Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:34Z DEBUG libipa_modrdn 2020-06-03T06:39:34Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:34Z DEBUG betxnpostoperation 2020-06-03T06:39:34Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:34Z DEBUG Red Hat, Inc. 2020-06-03T06:39:34Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:34Z DEBUG 1.0 2020-06-03T06:39:34Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG nsSlapdPlugin 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG [] 2020-06-03T06:39:34Z DEBUG Updated 0 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG [] 2020-06-03T06:39:34Z DEBUG Updated 0 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=config,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapd-lookthroughlimit: 2020-06-03T06:39:34Z DEBUG 5000 2020-06-03T06:39:34Z DEBUG nsslapd-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-idlistscanlimit: 2020-06-03T06:39:34Z DEBUG 4000 2020-06-03T06:39:34Z DEBUG nsslapd-directory: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/db 2020-06-03T06:39:34Z DEBUG nsslapd-dbcachesize: 2020-06-03T06:39:34Z DEBUG 39845888 2020-06-03T06:39:34Z DEBUG nsslapd-db-logdirectory: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/db 2020-06-03T06:39:34Z DEBUG nsslapd-db-durable-transaction: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-db-transaction-wait: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-db-checkpoint-interval: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-db-compactdb-interval: 2020-06-03T06:39:34Z DEBUG 2592000 2020-06-03T06:39:34Z DEBUG nsslapd-db-transaction-batch-val: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-db-transaction-batch-min-wait: 2020-06-03T06:39:34Z DEBUG 50 2020-06-03T06:39:34Z DEBUG nsslapd-db-transaction-batch-max-wait: 2020-06-03T06:39:34Z DEBUG 50 2020-06-03T06:39:34Z DEBUG nsslapd-db-logbuf-size: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-db-locks: 2020-06-03T06:39:34Z DEBUG 50000 2020-06-03T06:39:34Z DEBUG nsslapd-db-private-import-mem: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-import-cache-autosize: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-cache-autosize: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-cache-autosize-split: 2020-06-03T06:39:34Z DEBUG 25 2020-06-03T06:39:34Z DEBUG nsslapd-import-cachesize: 2020-06-03T06:39:34Z DEBUG 16777216 2020-06-03T06:39:34Z DEBUG nsslapd-idl-switch: 2020-06-03T06:39:34Z DEBUG new 2020-06-03T06:39:34Z DEBUG nsslapd-search-bypass-filter-test: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-search-use-vlv-index: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-exclude-from-export: 2020-06-03T06:39:34Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2020-06-03T06:39:34Z DEBUG nsslapd-serial-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-subtree-rename-switch: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-pagedlookthroughlimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-pagedidlistscanlimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-rangelookthroughlimit: 2020-06-03T06:39:34Z DEBUG 5000 2020-06-03T06:39:34Z DEBUG nsslapd-backend-opt-level: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-db-deadlock-policy: 2020-06-03T06:39:34Z DEBUG 9 2020-06-03T06:39:34Z DEBUG replace: updated value ['100000'] 2020-06-03T06:39:34Z DEBUG replace: updated value ['100000'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=config,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapd-lookthroughlimit: 2020-06-03T06:39:34Z DEBUG 100000 2020-06-03T06:39:34Z DEBUG nsslapd-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-idlistscanlimit: 2020-06-03T06:39:34Z DEBUG 100000 2020-06-03T06:39:34Z DEBUG nsslapd-directory: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/db 2020-06-03T06:39:34Z DEBUG nsslapd-dbcachesize: 2020-06-03T06:39:34Z DEBUG 39845888 2020-06-03T06:39:34Z DEBUG nsslapd-db-logdirectory: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/db 2020-06-03T06:39:34Z DEBUG nsslapd-db-durable-transaction: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-db-transaction-wait: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-db-checkpoint-interval: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-db-compactdb-interval: 2020-06-03T06:39:34Z DEBUG 2592000 2020-06-03T06:39:34Z DEBUG nsslapd-db-transaction-batch-val: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-db-transaction-batch-min-wait: 2020-06-03T06:39:34Z DEBUG 50 2020-06-03T06:39:34Z DEBUG nsslapd-db-transaction-batch-max-wait: 2020-06-03T06:39:34Z DEBUG 50 2020-06-03T06:39:34Z DEBUG nsslapd-db-logbuf-size: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-db-locks: 2020-06-03T06:39:34Z DEBUG 50000 2020-06-03T06:39:34Z DEBUG nsslapd-db-private-import-mem: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-import-cache-autosize: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-cache-autosize: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-cache-autosize-split: 2020-06-03T06:39:34Z DEBUG 25 2020-06-03T06:39:34Z DEBUG nsslapd-import-cachesize: 2020-06-03T06:39:34Z DEBUG 16777216 2020-06-03T06:39:34Z DEBUG nsslapd-idl-switch: 2020-06-03T06:39:34Z DEBUG new 2020-06-03T06:39:34Z DEBUG nsslapd-search-bypass-filter-test: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-search-use-vlv-index: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-exclude-from-export: 2020-06-03T06:39:34Z DEBUG entrydn entryid dncomp parentid numSubordinates tombstonenumsubordinates entryusn 2020-06-03T06:39:34Z DEBUG nsslapd-serial-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-subtree-rename-switch: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-pagedlookthroughlimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-pagedidlistscanlimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-rangelookthroughlimit: 2020-06-03T06:39:34Z DEBUG 5000 2020-06-03T06:39:34Z DEBUG nsslapd-backend-opt-level: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-db-deadlock-policy: 2020-06-03T06:39:34Z DEBUG 9 2020-06-03T06:39:34Z DEBUG [(2, 'nsslapd-lookthroughlimit', ['100000']), (2, 'nsslapd-idlistscanlimit', ['100000'])] 2020-06-03T06:39:34Z DEBUG Updated 1 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG anonymous-limits 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG nsContainer 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG anonymous-limits 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG nsContainer 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG [] 2020-06-03T06:39:34Z DEBUG Updated 0 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG only: set nsslapd-anonlimitsdn to 'cn=anonymous-limits,cn=etc,dc=ipa,dc=test', current value [''] 2020-06-03T06:39:34Z DEBUG only: updated value ['cn=anonymous-limits,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG [(2, 'nsslapd-anonlimitsdn', ['cn=anonymous-limits,cn=etc,dc=ipa,dc=test'])] 2020-06-03T06:39:34Z DEBUG Updated 1 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG add: 'dc=ipa,dc=test' to nsslapd-defaultNamingContext, current value ['dc=ipa,dc=test'] 2020-06-03T06:39:34Z DEBUG add: updated value ['dc=ipa,dc=test'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG [] 2020-06-03T06:39:34Z DEBUG Updated 0 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG only: set nsslapd-minssf-exclude-rootdse to 'on', current value ['off'] 2020-06-03T06:39:34Z DEBUG only: updated value ['on'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG [(2, 'nsslapd-minssf-exclude-rootdse', ['on'])] 2020-06-03T06:39:34Z DEBUG Updated 1 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG ipa-winsync 2020-06-03T06:39:34Z DEBUG ipawinsyncacctdisable: 2020-06-03T06:39:34Z DEBUG both 2020-06-03T06:39:34Z DEBUG ipawinsyncdefaultgroupattr: 2020-06-03T06:39:34Z DEBUG ipaDefaultPrimaryGroup 2020-06-03T06:39:34Z DEBUG ipawinsyncdefaultgroupfilter: 2020-06-03T06:39:34Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2020-06-03T06:39:34Z DEBUG ipawinsyncforcesync: 2020-06-03T06:39:34Z DEBUG true 2020-06-03T06:39:34Z DEBUG ipawinsynchomedirattr: 2020-06-03T06:39:34Z DEBUG ipaHomesRootDir 2020-06-03T06:39:34Z DEBUG ipawinsyncloginshellattr: 2020-06-03T06:39:34Z DEBUG ipaDefaultLoginShell 2020-06-03T06:39:34Z DEBUG ipawinsyncnewentryfilter: 2020-06-03T06:39:34Z DEBUG (cn=ipaConfig) 2020-06-03T06:39:34Z DEBUG ipawinsyncnewuserocattr: 2020-06-03T06:39:34Z DEBUG ipauserobjectclasses 2020-06-03T06:39:34Z DEBUG ipawinsyncrealmattr: 2020-06-03T06:39:34Z DEBUG cn 2020-06-03T06:39:34Z DEBUG ipawinsyncrealmfilter: 2020-06-03T06:39:34Z DEBUG (objectclass=krbRealmContainer) 2020-06-03T06:39:34Z DEBUG ipawinsyncuserattr: 2020-06-03T06:39:34Z DEBUG uidNumber -1 2020-06-03T06:39:34Z DEBUG gidNumber -1 2020-06-03T06:39:34Z DEBUG ipawinsyncuserflatten: 2020-06-03T06:39:34Z DEBUG true 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:34Z DEBUG database 2020-06-03T06:39:34Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:34Z DEBUG ipa winsync plugin 2020-06-03T06:39:34Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:34Z DEBUG ipa-winsync-plugin 2020-06-03T06:39:34Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:34Z DEBUG ipa_winsync_plugin_init 2020-06-03T06:39:34Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:34Z DEBUG libipa_winsync 2020-06-03T06:39:34Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:34Z DEBUG preoperation 2020-06-03T06:39:34Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:34Z DEBUG FreeIPA project 2020-06-03T06:39:34Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:34Z DEBUG FreeIPA/1.0 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG nsSlapdPlugin 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG only: set nsslapd-pluginPrecedence to '60', current value [] 2020-06-03T06:39:34Z DEBUG only: updated value ['60'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG ipa-winsync 2020-06-03T06:39:34Z DEBUG ipawinsyncacctdisable: 2020-06-03T06:39:34Z DEBUG both 2020-06-03T06:39:34Z DEBUG ipawinsyncdefaultgroupattr: 2020-06-03T06:39:34Z DEBUG ipaDefaultPrimaryGroup 2020-06-03T06:39:34Z DEBUG ipawinsyncdefaultgroupfilter: 2020-06-03T06:39:34Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2020-06-03T06:39:34Z DEBUG ipawinsyncforcesync: 2020-06-03T06:39:34Z DEBUG true 2020-06-03T06:39:34Z DEBUG ipawinsynchomedirattr: 2020-06-03T06:39:34Z DEBUG ipaHomesRootDir 2020-06-03T06:39:34Z DEBUG ipawinsyncloginshellattr: 2020-06-03T06:39:34Z DEBUG ipaDefaultLoginShell 2020-06-03T06:39:34Z DEBUG ipawinsyncnewentryfilter: 2020-06-03T06:39:34Z DEBUG (cn=ipaConfig) 2020-06-03T06:39:34Z DEBUG ipawinsyncnewuserocattr: 2020-06-03T06:39:34Z DEBUG ipauserobjectclasses 2020-06-03T06:39:34Z DEBUG ipawinsyncrealmattr: 2020-06-03T06:39:34Z DEBUG cn 2020-06-03T06:39:34Z DEBUG ipawinsyncrealmfilter: 2020-06-03T06:39:34Z DEBUG (objectclass=krbRealmContainer) 2020-06-03T06:39:34Z DEBUG ipawinsyncuserattr: 2020-06-03T06:39:34Z DEBUG uidNumber -1 2020-06-03T06:39:34Z DEBUG gidNumber -1 2020-06-03T06:39:34Z DEBUG ipawinsyncuserflatten: 2020-06-03T06:39:34Z DEBUG true 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:34Z DEBUG database 2020-06-03T06:39:34Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:34Z DEBUG ipa winsync plugin 2020-06-03T06:39:34Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:34Z DEBUG ipa-winsync-plugin 2020-06-03T06:39:34Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:34Z DEBUG ipa_winsync_plugin_init 2020-06-03T06:39:34Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:34Z DEBUG libipa_winsync 2020-06-03T06:39:34Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:34Z DEBUG preoperation 2020-06-03T06:39:34Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:34Z DEBUG FreeIPA project 2020-06-03T06:39:34Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:34Z DEBUG FreeIPA/1.0 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG nsSlapdPlugin 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapd-pluginPrecedence: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG [(2, 'nsslapd-pluginPrecedence', ['60'])] 2020-06-03T06:39:34Z DEBUG Updated 1 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG only: set nsslapd-sasl-mapping-fallback to 'on', current value ['on'] 2020-06-03T06:39:34Z DEBUG only: updated value ['on'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG config 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG extensibleObject 2020-06-03T06:39:34Z DEBUG nsslapdConfig 2020-06-03T06:39:34Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:34Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-betype: 2020-06-03T06:39:34Z DEBUG ldbm database 2020-06-03T06:39:34Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:34Z DEBUG cn=schema 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG cn=monitor 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-plugin: 2020-06-03T06:39:34Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:34Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:34Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:34Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:34Z DEBUG 16384 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-port: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-localuser: 2020-06-03T06:39:34Z DEBUG dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordInHistory: 2020-06-03T06:39:34Z DEBUG 6 2020-06-03T06:39:34Z DEBUG passwordUnlock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordGraceLimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG passwordMustChange: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:34Z DEBUG 2000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordWarning: 2020-06-03T06:39:34Z DEBUG 86400 2020-06-03T06:39:34Z DEBUG nsslapd-readonly: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:34Z DEBUG 16 2020-06-03T06:39:34Z DEBUG passwordLockout: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-localhost: 2020-06-03T06:39:34Z DEBUG replica1.ipa.test 2020-06-03T06:39:34Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:34Z DEBUG 10000 2020-06-03T06:39:34Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:34Z DEBUG 40 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG passwordMinLength: 2020-06-03T06:39:34Z DEBUG 8 2020-06-03T06:39:34Z DEBUG passwordMinDigits: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinAlphas: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinUppers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinLowers: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinSpecials: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMin8bit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMinCategories: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG passwordPalindrome: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictCheck: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordDictPath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordUserAttributes: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordBadWords: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordMaxSequence: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:34Z DEBUG replication-only 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 500 2020-06-03T06:39:34Z DEBUG passwordMaxFailure: 2020-06-03T06:39:34Z DEBUG 3 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:34Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-security: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordMaxAge: 2020-06-03T06:39:34Z DEBUG 8640000 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:34Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:34Z DEBUG passwordChange: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:34Z DEBUG 256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-securePort: 2020-06-03T06:39:34Z DEBUG 636 2020-06-03T06:39:34Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:34Z DEBUG 64 2020-06-03T06:39:34Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG passwordExp: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG day 2020-06-03T06:39:34Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:34Z DEBUG 3600 2020-06-03T06:39:34Z DEBUG nsslapd-nagle: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:34Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:34Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:34Z DEBUG uidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:34Z DEBUG gidNumber 2020-06-03T06:39:34Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:34Z DEBUG dc=example,dc=com 2020-06-03T06:39:34Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:34Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-counters: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:34Z DEBUG cn=Directory Manager 2020-06-03T06:39:34Z DEBUG passwordMinAge: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:34Z DEBUG 209715200 2020-06-03T06:39:34Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:34Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:34Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:34Z DEBUG 1048576 2020-06-03T06:39:34Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:34Z DEBUG 1024 2020-06-03T06:39:34Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:34Z DEBUG allowed 2020-06-03T06:39:34Z DEBUG nsslapd-config: 2020-06-03T06:39:34Z DEBUG cn=config 2020-06-03T06:39:34Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:34Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:34Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:34Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:34Z DEBUG /tmp 2020-06-03T06:39:34Z DEBUG nsslapd-certdir: 2020-06-03T06:39:34Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:34Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:34Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:34Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:34Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rundir: 2020-06-03T06:39:34Z DEBUG /var/run/dirsrv 2020-06-03T06:39:34Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:34Z DEBUG 300000 2020-06-03T06:39:34Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-localssf: 2020-06-03T06:39:34Z DEBUG 71 2020-06-03T06:39:34Z DEBUG nsslapd-minssf: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:34Z DEBUG next 2020-06-03T06:39:34Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:34Z DEBUG warn 2020-06-03T06:39:34Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:34Z DEBUG 60 2020-06-03T06:39:34Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:34Z DEBUG 20971520 2020-06-03T06:39:34Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:34Z DEBUG nolog 2020-06-03T06:39:34Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:34Z DEBUG 2097152 2020-06-03T06:39:34Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:34Z DEBUG 128 2020-06-03T06:39:34Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:34Z DEBUG -10 2020-06-03T06:39:34Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:34Z DEBUG -1 2020-06-03T06:39:34Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:34Z DEBUG 600 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:34Z DEBUG 0 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:34Z DEBUG 100 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:34Z DEBUG 1 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:34Z DEBUG 2 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:34Z DEBUG month 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:34Z DEBUG 5 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:34Z DEBUG week 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:34Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:34Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:34Z DEBUG dirsrv-log 2020-06-03T06:39:34Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:34Z DEBUG none 2020-06-03T06:39:34Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:34Z DEBUG process-safe 2020-06-03T06:39:34Z DEBUG passwordStorageScheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG passwordAdminDN: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:34Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:34Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:34Z DEBUG on 2020-06-03T06:39:34Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:34Z DEBUG off 2020-06-03T06:39:34Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:34Z DEBUG 2020-06-03T06:39:34Z DEBUG aci: 2020-06-03T06:39:34Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:34Z DEBUG [] 2020-06-03T06:39:34Z DEBUG Updated 0 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG Full Principal 2020-06-03T06:39:34Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsSaslMapFilterTemplate: 2020-06-03T06:39:34Z DEBUG (krbPrincipalName=\1@\2) 2020-06-03T06:39:34Z DEBUG nsSaslMapPriority: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsSaslMapRegexString: 2020-06-03T06:39:34Z DEBUG \(.*\)@\(.*\) 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG nsSaslMapping 2020-06-03T06:39:34Z DEBUG addifnew: '10' to nsSaslMapPriority, current value ['10'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=Full Principal,cn=mapping,cn=sasl,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG Full Principal 2020-06-03T06:39:34Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsSaslMapFilterTemplate: 2020-06-03T06:39:34Z DEBUG (krbPrincipalName=\1@\2) 2020-06-03T06:39:34Z DEBUG nsSaslMapPriority: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsSaslMapRegexString: 2020-06-03T06:39:34Z DEBUG \(.*\)@\(.*\) 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG nsSaslMapping 2020-06-03T06:39:34Z DEBUG [] 2020-06-03T06:39:34Z DEBUG Updated 0 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:34Z DEBUG Updating existing entry: cn=Name Only,cn=mapping,cn=sasl,cn=config 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Initial value 2020-06-03T06:39:34Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG Name Only 2020-06-03T06:39:34Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsSaslMapFilterTemplate: 2020-06-03T06:39:34Z DEBUG (krbPrincipalName=&@IPA.TEST) 2020-06-03T06:39:34Z DEBUG nsSaslMapPriority: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsSaslMapRegexString: 2020-06-03T06:39:34Z DEBUG ^[^:@]+$ 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG nsSaslMapping 2020-06-03T06:39:34Z DEBUG addifnew: '10' to nsSaslMapPriority, current value ['10'] 2020-06-03T06:39:34Z DEBUG --------------------------------------------- 2020-06-03T06:39:34Z DEBUG Final value after applying updates 2020-06-03T06:39:34Z DEBUG dn: cn=Name Only,cn=mapping,cn=sasl,cn=config 2020-06-03T06:39:34Z DEBUG cn: 2020-06-03T06:39:34Z DEBUG Name Only 2020-06-03T06:39:34Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-03T06:39:34Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:34Z DEBUG nsSaslMapFilterTemplate: 2020-06-03T06:39:34Z DEBUG (krbPrincipalName=&@IPA.TEST) 2020-06-03T06:39:34Z DEBUG nsSaslMapPriority: 2020-06-03T06:39:34Z DEBUG 10 2020-06-03T06:39:34Z DEBUG nsSaslMapRegexString: 2020-06-03T06:39:34Z DEBUG ^[^:@]+$ 2020-06-03T06:39:34Z DEBUG objectClass: 2020-06-03T06:39:34Z DEBUG top 2020-06-03T06:39:34Z DEBUG nsSaslMapping 2020-06-03T06:39:34Z DEBUG [] 2020-06-03T06:39:34Z DEBUG Updated 0 2020-06-03T06:39:34Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsslapdConfig 2020-06-03T06:39:35Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:35Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-betype: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:35Z DEBUG cn=schema 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG cn=monitor 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-plugin: 2020-06-03T06:39:35Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 10 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:35Z DEBUG 16384 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-port: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-localuser: 2020-06-03T06:39:35Z DEBUG dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordInHistory: 2020-06-03T06:39:35Z DEBUG 6 2020-06-03T06:39:35Z DEBUG passwordUnlock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordGraceLimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordMustChange: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:35Z DEBUG 2000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordWarning: 2020-06-03T06:39:35Z DEBUG 86400 2020-06-03T06:39:35Z DEBUG nsslapd-readonly: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:35Z DEBUG 16 2020-06-03T06:39:35Z DEBUG passwordLockout: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-localhost: 2020-06-03T06:39:35Z DEBUG replica1.ipa.test 2020-06-03T06:39:35Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:35Z DEBUG 10000 2020-06-03T06:39:35Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:35Z DEBUG 40 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordMinLength: 2020-06-03T06:39:35Z DEBUG 8 2020-06-03T06:39:35Z DEBUG passwordMinDigits: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinAlphas: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinUppers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinLowers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinSpecials: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMin8bit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinCategories: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordPalindrome: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictCheck: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictPath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordUserAttributes: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordBadWords: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordMaxSequence: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:35Z DEBUG replication-only 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 500 2020-06-03T06:39:35Z DEBUG passwordMaxFailure: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:35Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-security: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordMaxAge: 2020-06-03T06:39:35Z DEBUG 8640000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:35Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:35Z DEBUG passwordChange: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:35Z DEBUG 256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-securePort: 2020-06-03T06:39:35Z DEBUG 636 2020-06-03T06:39:35Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:35Z DEBUG 64 2020-06-03T06:39:35Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordExp: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG day 2020-06-03T06:39:35Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-nagle: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:35Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:35Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:35Z DEBUG uidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:35Z DEBUG gidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:35Z DEBUG dc=example,dc=com 2020-06-03T06:39:35Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:35Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-counters: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG passwordMinAge: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:35Z DEBUG 209715200 2020-06-03T06:39:35Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:35Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:35Z DEBUG 1048576 2020-06-03T06:39:35Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:35Z DEBUG 1024 2020-06-03T06:39:35Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:35Z DEBUG allowed 2020-06-03T06:39:35Z DEBUG nsslapd-config: 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:35Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:35Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:35Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:35Z DEBUG /tmp 2020-06-03T06:39:35Z DEBUG nsslapd-certdir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:35Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:35Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rundir: 2020-06-03T06:39:35Z DEBUG /var/run/dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:35Z DEBUG 300000 2020-06-03T06:39:35Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-localssf: 2020-06-03T06:39:35Z DEBUG 71 2020-06-03T06:39:35Z DEBUG nsslapd-minssf: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:35Z DEBUG next 2020-06-03T06:39:35Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:35Z DEBUG warn 2020-06-03T06:39:35Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:35Z DEBUG 20971520 2020-06-03T06:39:35Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:35Z DEBUG nolog 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:35Z DEBUG 128 2020-06-03T06:39:35Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:35Z DEBUG -1 2020-06-03T06:39:35Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:35Z DEBUG dirsrv-log 2020-06-03T06:39:35Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:35Z DEBUG process-safe 2020-06-03T06:39:35Z DEBUG passwordStorageScheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG passwordAdminDN: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG only: set nsslapd-allow-hashed-passwords to 'on', current value ['off'] 2020-06-03T06:39:35Z DEBUG only: updated value ['on'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsslapdConfig 2020-06-03T06:39:35Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:35Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-betype: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:35Z DEBUG cn=schema 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG cn=monitor 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-plugin: 2020-06-03T06:39:35Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 10 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:35Z DEBUG 16384 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-port: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-localuser: 2020-06-03T06:39:35Z DEBUG dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordInHistory: 2020-06-03T06:39:35Z DEBUG 6 2020-06-03T06:39:35Z DEBUG passwordUnlock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordGraceLimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordMustChange: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:35Z DEBUG 2000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordWarning: 2020-06-03T06:39:35Z DEBUG 86400 2020-06-03T06:39:35Z DEBUG nsslapd-readonly: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:35Z DEBUG 16 2020-06-03T06:39:35Z DEBUG passwordLockout: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-localhost: 2020-06-03T06:39:35Z DEBUG replica1.ipa.test 2020-06-03T06:39:35Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:35Z DEBUG 10000 2020-06-03T06:39:35Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:35Z DEBUG 40 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordMinLength: 2020-06-03T06:39:35Z DEBUG 8 2020-06-03T06:39:35Z DEBUG passwordMinDigits: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinAlphas: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinUppers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinLowers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinSpecials: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMin8bit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinCategories: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordPalindrome: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictCheck: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictPath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordUserAttributes: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordBadWords: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordMaxSequence: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:35Z DEBUG replication-only 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 500 2020-06-03T06:39:35Z DEBUG passwordMaxFailure: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:35Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-security: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordMaxAge: 2020-06-03T06:39:35Z DEBUG 8640000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:35Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:35Z DEBUG passwordChange: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:35Z DEBUG 256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-securePort: 2020-06-03T06:39:35Z DEBUG 636 2020-06-03T06:39:35Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:35Z DEBUG 64 2020-06-03T06:39:35Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordExp: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG day 2020-06-03T06:39:35Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-nagle: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:35Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:35Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:35Z DEBUG uidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:35Z DEBUG gidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:35Z DEBUG dc=example,dc=com 2020-06-03T06:39:35Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:35Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-counters: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG passwordMinAge: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:35Z DEBUG 209715200 2020-06-03T06:39:35Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:35Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:35Z DEBUG 1048576 2020-06-03T06:39:35Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:35Z DEBUG 1024 2020-06-03T06:39:35Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:35Z DEBUG allowed 2020-06-03T06:39:35Z DEBUG nsslapd-config: 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:35Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:35Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:35Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:35Z DEBUG /tmp 2020-06-03T06:39:35Z DEBUG nsslapd-certdir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:35Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:35Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rundir: 2020-06-03T06:39:35Z DEBUG /var/run/dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:35Z DEBUG 300000 2020-06-03T06:39:35Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-localssf: 2020-06-03T06:39:35Z DEBUG 71 2020-06-03T06:39:35Z DEBUG nsslapd-minssf: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:35Z DEBUG next 2020-06-03T06:39:35Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:35Z DEBUG warn 2020-06-03T06:39:35Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:35Z DEBUG 20971520 2020-06-03T06:39:35Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:35Z DEBUG nolog 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:35Z DEBUG 128 2020-06-03T06:39:35Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:35Z DEBUG -1 2020-06-03T06:39:35Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:35Z DEBUG dirsrv-log 2020-06-03T06:39:35Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:35Z DEBUG process-safe 2020-06-03T06:39:35Z DEBUG passwordStorageScheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG passwordAdminDN: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG [(2, 'nsslapd-allow-hashed-passwords', ['on'])] 2020-06-03T06:39:35Z DEBUG Updated 1 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsslapdConfig 2020-06-03T06:39:35Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:35Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-betype: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:35Z DEBUG cn=schema 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG cn=monitor 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-plugin: 2020-06-03T06:39:35Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 10 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:35Z DEBUG 16384 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-port: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-localuser: 2020-06-03T06:39:35Z DEBUG dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordInHistory: 2020-06-03T06:39:35Z DEBUG 6 2020-06-03T06:39:35Z DEBUG passwordUnlock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordGraceLimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordMustChange: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:35Z DEBUG 2000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordWarning: 2020-06-03T06:39:35Z DEBUG 86400 2020-06-03T06:39:35Z DEBUG nsslapd-readonly: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:35Z DEBUG 16 2020-06-03T06:39:35Z DEBUG passwordLockout: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-localhost: 2020-06-03T06:39:35Z DEBUG replica1.ipa.test 2020-06-03T06:39:35Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:35Z DEBUG 10000 2020-06-03T06:39:35Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:35Z DEBUG 40 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordMinLength: 2020-06-03T06:39:35Z DEBUG 8 2020-06-03T06:39:35Z DEBUG passwordMinDigits: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinAlphas: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinUppers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinLowers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinSpecials: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMin8bit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinCategories: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordPalindrome: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictCheck: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictPath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordUserAttributes: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordBadWords: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordMaxSequence: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:35Z DEBUG replication-only 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 500 2020-06-03T06:39:35Z DEBUG passwordMaxFailure: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:35Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-security: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordMaxAge: 2020-06-03T06:39:35Z DEBUG 8640000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:35Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:35Z DEBUG passwordChange: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:35Z DEBUG 256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-securePort: 2020-06-03T06:39:35Z DEBUG 636 2020-06-03T06:39:35Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:35Z DEBUG 64 2020-06-03T06:39:35Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordExp: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG day 2020-06-03T06:39:35Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-nagle: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:35Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:35Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:35Z DEBUG uidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:35Z DEBUG gidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:35Z DEBUG dc=example,dc=com 2020-06-03T06:39:35Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:35Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-counters: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG passwordMinAge: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:35Z DEBUG 209715200 2020-06-03T06:39:35Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:35Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:35Z DEBUG 1048576 2020-06-03T06:39:35Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:35Z DEBUG 1024 2020-06-03T06:39:35Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:35Z DEBUG allowed 2020-06-03T06:39:35Z DEBUG nsslapd-config: 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:35Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:35Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:35Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:35Z DEBUG /tmp 2020-06-03T06:39:35Z DEBUG nsslapd-certdir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:35Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:35Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rundir: 2020-06-03T06:39:35Z DEBUG /var/run/dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:35Z DEBUG 300000 2020-06-03T06:39:35Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-localssf: 2020-06-03T06:39:35Z DEBUG 71 2020-06-03T06:39:35Z DEBUG nsslapd-minssf: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:35Z DEBUG next 2020-06-03T06:39:35Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:35Z DEBUG warn 2020-06-03T06:39:35Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:35Z DEBUG 20971520 2020-06-03T06:39:35Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:35Z DEBUG nolog 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:35Z DEBUG 128 2020-06-03T06:39:35Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:35Z DEBUG -1 2020-06-03T06:39:35Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:35Z DEBUG dirsrv-log 2020-06-03T06:39:35Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:35Z DEBUG process-safe 2020-06-03T06:39:35Z DEBUG passwordStorageScheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG passwordAdminDN: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG only: set nsslapd-ioblocktimeout to '10000', current value ['10000'] 2020-06-03T06:39:35Z DEBUG only: updated value ['10000'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsslapdConfig 2020-06-03T06:39:35Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:35Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-betype: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:35Z DEBUG cn=schema 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG cn=monitor 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-plugin: 2020-06-03T06:39:35Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 10 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:35Z DEBUG 16384 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-port: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-localuser: 2020-06-03T06:39:35Z DEBUG dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordInHistory: 2020-06-03T06:39:35Z DEBUG 6 2020-06-03T06:39:35Z DEBUG passwordUnlock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordGraceLimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordMustChange: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:35Z DEBUG 2000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordWarning: 2020-06-03T06:39:35Z DEBUG 86400 2020-06-03T06:39:35Z DEBUG nsslapd-readonly: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:35Z DEBUG 16 2020-06-03T06:39:35Z DEBUG passwordLockout: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-localhost: 2020-06-03T06:39:35Z DEBUG replica1.ipa.test 2020-06-03T06:39:35Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:35Z DEBUG 10000 2020-06-03T06:39:35Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:35Z DEBUG 40 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordMinLength: 2020-06-03T06:39:35Z DEBUG 8 2020-06-03T06:39:35Z DEBUG passwordMinDigits: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinAlphas: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinUppers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinLowers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinSpecials: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMin8bit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinCategories: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordPalindrome: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictCheck: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictPath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordUserAttributes: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordBadWords: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordMaxSequence: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:35Z DEBUG replication-only 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 500 2020-06-03T06:39:35Z DEBUG passwordMaxFailure: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:35Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-security: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordMaxAge: 2020-06-03T06:39:35Z DEBUG 8640000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:35Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:35Z DEBUG passwordChange: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:35Z DEBUG 256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-securePort: 2020-06-03T06:39:35Z DEBUG 636 2020-06-03T06:39:35Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:35Z DEBUG 64 2020-06-03T06:39:35Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordExp: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG day 2020-06-03T06:39:35Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-nagle: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:35Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:35Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:35Z DEBUG uidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:35Z DEBUG gidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:35Z DEBUG dc=example,dc=com 2020-06-03T06:39:35Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:35Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-counters: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG passwordMinAge: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:35Z DEBUG 209715200 2020-06-03T06:39:35Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:35Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:35Z DEBUG 1048576 2020-06-03T06:39:35Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:35Z DEBUG 1024 2020-06-03T06:39:35Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:35Z DEBUG allowed 2020-06-03T06:39:35Z DEBUG nsslapd-config: 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:35Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:35Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:35Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:35Z DEBUG /tmp 2020-06-03T06:39:35Z DEBUG nsslapd-certdir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:35Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:35Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rundir: 2020-06-03T06:39:35Z DEBUG /var/run/dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:35Z DEBUG 300000 2020-06-03T06:39:35Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-localssf: 2020-06-03T06:39:35Z DEBUG 71 2020-06-03T06:39:35Z DEBUG nsslapd-minssf: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:35Z DEBUG next 2020-06-03T06:39:35Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:35Z DEBUG warn 2020-06-03T06:39:35Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:35Z DEBUG 20971520 2020-06-03T06:39:35Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:35Z DEBUG nolog 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:35Z DEBUG 128 2020-06-03T06:39:35Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:35Z DEBUG -1 2020-06-03T06:39:35Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:35Z DEBUG dirsrv-log 2020-06-03T06:39:35Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:35Z DEBUG process-safe 2020-06-03T06:39:35Z DEBUG passwordStorageScheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG passwordAdminDN: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-config.update 0.552 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/10-enable-betxn.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG 7-bit check 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce 7-bit clean attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NS7bitAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NS7bitAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg0: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg1: 2020-06-03T06:39:35Z DEBUG mail 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg2: 2020-06-03T06:39:35Z DEBUG , 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg3: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG 7-bit check 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce 7-bit clean attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NS7bitAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NS7bitAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg0: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg1: 2020-06-03T06:39:35Z DEBUG mail 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg2: 2020-06-03T06:39:35Z DEBUG , 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg3: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=attribute uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG attribute uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=attribute uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG attribute uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG automemberprocessmodifyops: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Auto Membership Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Auto Membership plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Auto Membership 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG automember_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libautomember-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG automemberprocessmodifyops: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Auto Membership Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Auto Membership plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Auto Membership 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG automember_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libautomember-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Linked Attributes 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Linked Attributes plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Linked Attributes 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG linked_attrs_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG liblinkedattrs-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Linked Attributes 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Linked Attributes plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Linked Attributes 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG linked_attrs_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG liblinkedattrs-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Managed Entries plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG mep_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libmanagedentries-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Managed Entries plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG mep_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libmanagedentries-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG MemberOf Plugin 2020-06-03T06:39:35Z DEBUG memberofattr: 2020-06-03T06:39:35Z DEBUG memberOf 2020-06-03T06:39:35Z DEBUG memberofgroupattr: 2020-06-03T06:39:35Z DEBUG member 2020-06-03T06:39:35Z DEBUG memberUser 2020-06-03T06:39:35Z DEBUG memberHost 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG memberof plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG memberof 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG memberof_postop_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libmemberof-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpostoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG MemberOf Plugin 2020-06-03T06:39:35Z DEBUG memberofattr: 2020-06-03T06:39:35Z DEBUG memberOf 2020-06-03T06:39:35Z DEBUG memberofgroupattr: 2020-06-03T06:39:35Z DEBUG member 2020-06-03T06:39:35Z DEBUG memberUser 2020-06-03T06:39:35Z DEBUG memberHost 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG memberof plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG memberof 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG memberof_postop_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libmemberof-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Multimaster Replication Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG AES 2020-06-03T06:39:35Z DEBUG Class of Service 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Multi-master Replication Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG replication-multimaster 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG replication_multimaster_plugin_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libreplication-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2020-06-03T06:39:35Z DEBUG only: updated value ['on'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Multimaster Replication Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG AES 2020-06-03T06:39:35Z DEBUG Class of Service 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Multi-master Replication Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG replication-multimaster 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG replication_multimaster_plugin_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libreplication-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=PAM Pass Through Auth,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG PAM Pass Through Auth 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG pam_passthruauth_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libpam-passthru-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginloadglobal: 2020-06-03T06:39:35Z DEBUG true 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG pamConfig 2020-06-03T06:39:35Z DEBUG pamExcludeSuffix: 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG pamFallback: 2020-06-03T06:39:35Z DEBUG FALSE 2020-06-03T06:39:35Z DEBUG pamIDAttr: 2020-06-03T06:39:35Z DEBUG notUsedWithRDNMethod 2020-06-03T06:39:35Z DEBUG pamIDMapMethod: 2020-06-03T06:39:35Z DEBUG RDN 2020-06-03T06:39:35Z DEBUG pamMissingSuffix: 2020-06-03T06:39:35Z DEBUG ALLOW 2020-06-03T06:39:35Z DEBUG pamSecure: 2020-06-03T06:39:35Z DEBUG TRUE 2020-06-03T06:39:35Z DEBUG pamService: 2020-06-03T06:39:35Z DEBUG ldapserver 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginType to 'betxnpreoperation', current value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpreoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=PAM Pass Through Auth,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG PAM Pass Through Auth 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG pam_passthruauth_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libpam-passthru-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-pluginloadglobal: 2020-06-03T06:39:35Z DEBUG true 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG pamConfig 2020-06-03T06:39:35Z DEBUG pamExcludeSuffix: 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG pamFallback: 2020-06-03T06:39:35Z DEBUG FALSE 2020-06-03T06:39:35Z DEBUG pamIDAttr: 2020-06-03T06:39:35Z DEBUG notUsedWithRDNMethod 2020-06-03T06:39:35Z DEBUG pamIDMapMethod: 2020-06-03T06:39:35Z DEBUG RDN 2020-06-03T06:39:35Z DEBUG pamMissingSuffix: 2020-06-03T06:39:35Z DEBUG ALLOW 2020-06-03T06:39:35Z DEBUG pamSecure: 2020-06-03T06:39:35Z DEBUG TRUE 2020-06-03T06:39:35Z DEBUG pamService: 2020-06-03T06:39:35Z DEBUG ldapserver 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG referential integrity postoperation 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG referential integrity plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG referint 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG referint_postop_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libreferint-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:35Z DEBUG 40 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG referint-logfile: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/referint 2020-06-03T06:39:35Z DEBUG referint-membership-attr: 2020-06-03T06:39:35Z DEBUG member 2020-06-03T06:39:35Z DEBUG uniquemember 2020-06-03T06:39:35Z DEBUG owner 2020-06-03T06:39:35Z DEBUG seeAlso 2020-06-03T06:39:35Z DEBUG referint-update-delay: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpostoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG referential integrity postoperation 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG referential integrity plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG referint 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG referint_postop_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libreferint-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:35Z DEBUG 40 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG referint-logfile: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/referint 2020-06-03T06:39:35Z DEBUG referint-membership-attr: 2020-06-03T06:39:35Z DEBUG member 2020-06-03T06:39:35Z DEBUG uniquemember 2020-06-03T06:39:35Z DEBUG owner 2020-06-03T06:39:35Z DEBUG seeAlso 2020-06-03T06:39:35Z DEBUG referint-update-delay: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Roles Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG Views 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG roles plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG roles 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG roles_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libroles-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2020-06-03T06:39:35Z DEBUG only: updated value ['on'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Roles Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG Views 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG roles plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG roles 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG roles_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libroles-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG state change notification service plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG statechange 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG statechange_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libstatechange-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginType to 'betxnpostoperation', current value ['betxnpostoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpostoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG state change notification service plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG statechange 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG statechange_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libstatechange-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=USN,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=USN,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG USN 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG USN (Update Sequence Number) plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG USN 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG usn_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libusn-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2020-06-03T06:39:35Z DEBUG only: updated value ['on'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=USN,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG USN 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG USN (Update Sequence Number) plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG USN 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG usn_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libusn-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG IPA MODRDN 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG IPA MODRDN plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG IPA MODRDN 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG ipamodrdn_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libipa_modrdn 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Red Hat, Inc. 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG only: set nsslapd-plugintype to 'betxnpostoperation', current value ['betxnpostoperation'] 2020-06-03T06:39:35Z DEBUG only: updated value ['betxnpostoperation'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=IPA MODRDN,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG IPA MODRDN 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG IPA MODRDN plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG IPA MODRDN 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG ipamodrdn_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libipa_modrdn 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Red Hat, Inc. 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa_pwd_extop 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG IPA Password Extended Operation plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG IPA Password Manager 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG ipapwd_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libipa_pwd_extop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG extendedop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG FreeIPA project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG FreeIPA/1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-realmtree: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginbetxn to 'on', current value ['on'] 2020-06-03T06:39:35Z DEBUG only: updated value ['on'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa_pwd_extop 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG IPA Password Extended Operation plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG IPA Password Manager 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG ipapwd_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libipa_pwd_extop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG extendedop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG FreeIPA project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG FreeIPA/1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-realmtree: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG New entry: cn=NIS Server,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG onlyifexist: 'on' to nsslapd-pluginbetxn, current value [] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=NIS Server,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-enable-betxn.update 0.055 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/10-ipapwd.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa_pwd_extop 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG IPA Password Extended Operation plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG IPA Password Manager 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG ipapwd_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libipa_pwd_extop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG extendedop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG FreeIPA project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG FreeIPA/1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-realmtree: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG add: '49' to nsslapd-pluginprecedence, current value [] 2020-06-03T06:39:35Z DEBUG add: updated value ['49'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ipa_pwd_extop,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa_pwd_extop 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG IPA Password Extended Operation plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG IPA Password Manager 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG ipapwd_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libipa_pwd_extop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG extendedop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG FreeIPA project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG FreeIPA/1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-realmtree: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:35Z DEBUG 49 2020-06-03T06:39:35Z DEBUG [(2, 'nsslapd-pluginprecedence', ['49'])] 2020-06-03T06:39:35Z DEBUG Updated 1 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-ipapwd.update 0.016 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/10-rootdse.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG defaultnamingcontext: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG dataversion: 2020-06-03T06:39:35Z DEBUG 020200603063933020200603063933 2020-06-03T06:39:35Z DEBUG netscapemdsuffix: 2020-06-03T06:39:35Z DEBUG cn=ldap://dc=replica1,dc=ipa,dc=test:0 2020-06-03T06:39:35Z DEBUG lastusn: 2020-06-03T06:39:35Z DEBUG 129 2020-06-03T06:39:35Z DEBUG ipatopologypluginversion: 2020-06-03T06:39:35Z DEBUG 1.0 2020-06-03T06:39:35Z DEBUG ipatopologyismanaged: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG ipaDomainLevel: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG add: 'namingContexts' to nsslapd-return-default-opattr, current value [] 2020-06-03T06:39:35Z DEBUG add: updated value ['namingContexts'] 2020-06-03T06:39:35Z DEBUG add: 'supportedControl' to nsslapd-return-default-opattr, current value ['namingContexts'] 2020-06-03T06:39:35Z DEBUG add: updated value ['namingContexts', 'supportedControl'] 2020-06-03T06:39:35Z DEBUG add: 'supportedExtension' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl'] 2020-06-03T06:39:35Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension'] 2020-06-03T06:39:35Z DEBUG add: 'supportedLDAPVersion' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension'] 2020-06-03T06:39:35Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion'] 2020-06-03T06:39:35Z DEBUG add: 'supportedSASLMechanisms' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion'] 2020-06-03T06:39:35Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms'] 2020-06-03T06:39:35Z DEBUG add: 'vendorName' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms'] 2020-06-03T06:39:35Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName'] 2020-06-03T06:39:35Z DEBUG add: 'vendorVersion' to nsslapd-return-default-opattr, current value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName'] 2020-06-03T06:39:35Z DEBUG add: updated value ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName', 'vendorVersion'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG defaultnamingcontext: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG dataversion: 2020-06-03T06:39:35Z DEBUG 020200603063933020200603063933 2020-06-03T06:39:35Z DEBUG netscapemdsuffix: 2020-06-03T06:39:35Z DEBUG cn=ldap://dc=replica1,dc=ipa,dc=test:0 2020-06-03T06:39:35Z DEBUG lastusn: 2020-06-03T06:39:35Z DEBUG 129 2020-06-03T06:39:35Z DEBUG ipatopologypluginversion: 2020-06-03T06:39:35Z DEBUG 1.0 2020-06-03T06:39:35Z DEBUG ipatopologyismanaged: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG ipaDomainLevel: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr != "aci")(version 3.0; aci "rootdse anon read access"; allow(read,search,compare) userdn="ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG nsslapd-return-default-opattr: 2020-06-03T06:39:35Z DEBUG namingContexts 2020-06-03T06:39:35Z DEBUG supportedControl 2020-06-03T06:39:35Z DEBUG supportedExtension 2020-06-03T06:39:35Z DEBUG supportedLDAPVersion 2020-06-03T06:39:35Z DEBUG supportedSASLMechanisms 2020-06-03T06:39:35Z DEBUG vendorName 2020-06-03T06:39:35Z DEBUG vendorVersion 2020-06-03T06:39:35Z DEBUG [(2, 'nsslapd-return-default-opattr', ['namingContexts', 'supportedControl', 'supportedExtension', 'supportedLDAPVersion', 'supportedSASLMechanisms', 'vendorName', 'vendorVersion'])] 2020-06-03T06:39:35Z DEBUG Updated 1 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-rootdse.update 0.020 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/10-selinuxusermap.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=selinux,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=selinux,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG selinux 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=selinux,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG selinux 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=usermap,cn=selinux,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=usermap,cn=selinux,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG usermap 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Add SELinux User Maps";allow (add) groupdn = "ldap:///cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || ipaenabledflag || ipaselinuxuser || memberhost || memberuser || seealso")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Modify SELinux User Maps";allow (write) groupdn = "ldap:///cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "accesstime || cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipaselinuxuser || ipauniqueid || member || memberhost || memberuser || modifytimestamp || objectclass || seealso || usercategory")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Read SELinux User Maps";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Remove SELinux User Maps";allow (delete) groupdn = "ldap:///cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=usermap,cn=selinux,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG usermap 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Add SELinux User Maps";allow (add) groupdn = "ldap:///cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || ipaenabledflag || ipaselinuxuser || memberhost || memberuser || seealso")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Modify SELinux User Maps";allow (write) groupdn = "ldap:///cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "accesstime || cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipaselinuxuser || ipauniqueid || member || memberhost || memberuser || modifytimestamp || objectclass || seealso || usercategory")(targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Read SELinux User Maps";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipaselinuxusermap)")(version 3.0;acl "permission:System: Remove SELinux User Maps";allow (delete) groupdn = "ldap:///cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-selinuxusermap.update 0.004 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/10-uniqueness.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=sudorule name uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG sudorule name uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG cn 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG cn=sudorules,cn=sudo,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=sudorule name uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG sudorule name uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG cn 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG cn=sudorules,cn=sudo,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG New entry: cn=certificate store subject uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG certificate store subject uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG ipaCertSubject 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=certificate store subject uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG certificate store subject uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG ipaCertSubject 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG New entry: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG certificate store issuer/serial uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG ipaCertIssuerSerial 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=certificate store issuer/serial uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG certificate store issuer/serial uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG ipaCertIssuerSerial 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG New entry: cn=uid uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG uid uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=compat,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-subtree-entries-oc: 2020-06-03T06:39:35Z DEBUG posixAccount 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG uid uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=compat,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-subtree-entries-oc: 2020-06-03T06:39:35Z DEBUG posixAccount 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=uid uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG uid uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=compat,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-subtree-entries-oc: 2020-06-03T06:39:35Z DEBUG posixAccount 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG add: 'cn=compat,dc=ipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=compat,dc=ipa,dc=test', 'cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test', 'cn=compat,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test', 'cn=compat,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG add: updated value ['cn=compat,dc=ipa,dc=test', 'cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG remove: 'off' from uniqueness-across-all-subtrees, current value ['on'] 2020-06-03T06:39:35Z DEBUG remove: 'off' not in uniqueness-across-all-subtrees 2020-06-03T06:39:35Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2020-06-03T06:39:35Z DEBUG add: updated value ['on'] 2020-06-03T06:39:35Z DEBUG add: 'posixAccount' to uniqueness-subtree-entries-oc, current value ['posixAccount'] 2020-06-03T06:39:35Z DEBUG add: updated value ['posixAccount'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=uid uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG uid uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=compat,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-subtree-entries-oc: 2020-06-03T06:39:35Z DEBUG posixAccount 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG krbPrincipalName uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG krbPrincipalName 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2020-06-03T06:39:35Z DEBUG add: updated value ['on'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=krbPrincipalName uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG krbPrincipalName uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG krbPrincipalName 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG krbCanonicalName uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG krbCanonicalName 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2020-06-03T06:39:35Z DEBUG add: updated value ['on'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=krbCanonicalName uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG krbCanonicalName uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG krbCanonicalName 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipaUniqueID uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG ipaUniqueID 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG add: 'cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test' to uniqueness-exclude-subtrees, current value ['cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG add: updated value ['cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG add: 'on' to uniqueness-across-all-subtrees, current value ['on'] 2020-06-03T06:39:35Z DEBUG add: updated value ['on'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ipaUniqueID uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipaUniqueID uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG uniqueness-across-all-subtrees: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG ipaUniqueID 2020-06-03T06:39:35Z DEBUG uniqueness-exclude-subtrees: 2020-06-03T06:39:35Z DEBUG cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG New entry: cn=caacl name uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=caacl name uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG caacl name uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG cn 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG cn=caacls,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=caacl name uniqueness,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG caacl name uniqueness 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce unique attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG uniqueness-attribute-name: 2020-06-03T06:39:35Z DEBUG cn 2020-06-03T06:39:35Z DEBUG uniqueness-subtrees: 2020-06-03T06:39:35Z DEBUG cn=caacls,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NSUniqueAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.1.0 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG Fedora Project 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/10-uniqueness.update 0.084 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/19-managed-entries.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Managed Entries plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG mep_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libmanagedentries-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG only: set nsslapd-pluginConfigArea to 'cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test', current value ['cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG only: updated value ['cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Managed Entries plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG mep_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libmanagedentries-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Templates 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Templates 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Definitions 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Definitions 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/19-managed-entries.update 0.009 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/20-aci.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ng,cn=alt,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ng,cn=alt,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ng 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)' to aci, current value ['(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ng,cn=alt,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ng 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Add Netgroups";allow (add) groupdn = "ldap:///cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "externalhost || member || memberhost || memberuser")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "description")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Modify Netgroups";allow (write) groupdn = "ldap:///cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || externalhost || member || memberhost || memberof || memberuser || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipaenabledflag || ipauniqueid || modifytimestamp || nisdomainname || objectclass || usercategory")(targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Read Netgroups";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipanisnetgroup)")(version 3.0;acl "permission:System: Remove Netgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=mepManagedEntry)")(targetattr = "*")(version 3.0; acl "Managed netgroups cannot be modified"; deny (write) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG accounts 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG accounts 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG computers 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)' to aci, current value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG computers 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG computers 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)' to aci, current value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG computers 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr="usercertificate || krblastpwdchange || description || l || nshostlocation || nshardwareplatform || nsosversion")(version 3.0; acl "Hosts can modify their own certs and keytabs"; allow(write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can modify their own SSH public keys"; allow(write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage other host Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage host keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Add Hosts";allow (add) groupdn = "ldap:///cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbprincipalname")(targetfilter = "(&(!(krbprincipalname=*))(objectclass=ipahost))")(version 3.0;acl "permission:System: Add krbPrincipalName to a Host";allow (write) groupdn = "ldap:///cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "enrolledby || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Enroll a Host";allow (write) groupdn = "ldap:///cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Certificates";allow (write) groupdn = "ldap:///cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Enrollment Password";allow (write) groupdn = "ldap:///cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(&(!(memberOf=cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test))(objectclass=ipahost))")(version 3.0;acl "permission:System: Manage Host Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host Principals";allow (write) groupdn = "ldap:///cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Manage Host SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "description || ipaassignedidview || krbprincipalauthind || l || macaddress || nshardwareplatform || nshostlocation || nsosversion || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Modify Hosts";allow (write) groupdn = "ldap:///cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Host Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || enrolledby || entryusn || fqdn || ipaassignedidview || ipaclientversion || ipakrbauthzdata || ipasshpubkey || ipauniqueid || krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || l || macaddress || managedby || modifytimestamp || nshardwareplatform || nshostlocation || nsosversion || objectclass || serverhostname || usercertificate || userclass")(targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Read Hosts";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahost)")(version 3.0;acl "permission:System: Remove Hosts";allow (delete) groupdn = "ldap:///cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipasshpubkey")(version 3.0; acl "Hosts can manage other host SSH public keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG add: '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG add: '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG replicas 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' from aci, current value [] 2020-06-03T06:39:35Z DEBUG remove: '(targetfilter="(objectclass=nsContainer)")(version 3.0; acl "Deny read access to replica configuration"; deny(read, search, compare) userdn = "ldap:///anyone";)' not in aci 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG replicas 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG masters 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG masters 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG masters 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG masters 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG masters 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG masters 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG sysaccounts 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG sysaccounts 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG kerberos 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)' to aci, current value ['(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG kerberos 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || objectclass")(targetfilter = "(|(objectclass=krbrealmcontainer)(objectclass=krbcontainer))")(version 3.0;acl "Anonymous read access to Kerberos containers";allow (read,compare,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || krbTicketFlags || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPrincipalExpiration || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbUPEnabled || krbTicketPolicyReference || krbPasswordExpiration || krbPwdPolicyReference || krbPrincipalType || krbPwdHistory || krbLastPwdChange || krbPrincipalAliases || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || krbLoginFailedCount || ipaUniqueId || memberOf || serverHostName || enrolledBy || ipaNTHash")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG add: '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG add: '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=tasks,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=tasks,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG tasks 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=tasks,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG tasks 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0; acl "Run tasks after replica re-initialization"; allow (add) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0; acl "cert manager: Run tasks after replica re-initialization"; allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG (targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [(0, 'aci', ['(targetattr="*")(version 3.0; acl "Admin can read all tasks"; allow (read, compare, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'])] 2020-06-03T06:39:35Z DEBUG Updated 1 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG mapping tree 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG mapping tree 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'])] 2020-06-03T06:39:35Z DEBUG Updated 1 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG mapping tree 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG mapping tree 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=meTo($dn),cn=*,cn=mapping tree,cn=config")(targetattr = "objectclass || cn")(version 3.0; acl "Allow hosts to read their replication agreements"; allow(read, search, compare) userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG dc\=ipa\,dc\=test 2020-06-03T06:39:35Z DEBUG nsslapd-backend: 2020-06-03T06:39:35Z DEBUG userRoot 2020-06-03T06:39:35Z DEBUG nsslapd-referral: 2020-06-03T06:39:35Z DEBUG ldap://replica1.ipa.test:389/dc%3Dipa%2Cdc%3Dtest 2020-06-03T06:39:35Z DEBUG ldap://master1.ipa.test:389/dc%3Dipa%2Cdc%3Dtest 2020-06-03T06:39:35Z DEBUG nsslapd-state: 2020-06-03T06:39:35Z DEBUG backend 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsMappingTree 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value [] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value [] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value [] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=dc\=ipa\,dc\=test,cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG dc\=ipa\,dc\=test 2020-06-03T06:39:35Z DEBUG nsslapd-backend: 2020-06-03T06:39:35Z DEBUG userRoot 2020-06-03T06:39:35Z DEBUG nsslapd-referral: 2020-06-03T06:39:35Z DEBUG ldap://replica1.ipa.test:389/dc%3Dipa%2Cdc%3Dtest 2020-06-03T06:39:35Z DEBUG ldap://master1.ipa.test:389/dc%3Dipa%2Cdc%3Dtest 2020-06-03T06:39:35Z DEBUG nsslapd-state: 2020-06-03T06:39:35Z DEBUG backend 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsMappingTree 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG o=ipaca 2020-06-03T06:39:35Z DEBUG nsslapd-backend: 2020-06-03T06:39:35Z DEBUG ipaca 2020-06-03T06:39:35Z DEBUG nsslapd-referral: 2020-06-03T06:39:35Z DEBUG ldap://replica1.ipa.test:389/o%3Dipaca 2020-06-03T06:39:35Z DEBUG ldap://master1.ipa.test:389/o%3Dipaca 2020-06-03T06:39:35Z DEBUG nsslapd-state: 2020-06-03T06:39:35Z DEBUG backend 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsMappingTree 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value ['(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(version 3.0;acl "permission:Add Replication Agreements";allow (add) groupdn = "ldap:///cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value ['(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "permission:Modify Replication Agreements"; allow (read, write, search) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value ['(targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "permission:Remove Replication Agreements";allow (delete) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG o=ipaca 2020-06-03T06:39:35Z DEBUG nsslapd-backend: 2020-06-03T06:39:35Z DEBUG ipaca 2020-06-03T06:39:35Z DEBUG nsslapd-referral: 2020-06-03T06:39:35Z DEBUG ldap://replica1.ipa.test:389/o%3Dipaca 2020-06-03T06:39:35Z DEBUG ldap://master1.ipa.test:389/o%3Dipaca 2020-06-03T06:39:35Z DEBUG nsslapd-state: 2020-06-03T06:39:35Z DEBUG backend 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsMappingTree 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr=*)(version 3.0;acl "cert manager: Add Replication Agreements";allow (add) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0; acl "cert manager: Modify Replication Agreements"; allow (read, write, search) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG (targetattr=*)(targetfilter="(|(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement))")(version 3.0;acl "cert manager: Remove Replication Agreements";allow (delete) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsslapdConfig 2020-06-03T06:39:35Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:35Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-betype: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:35Z DEBUG cn=schema 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG cn=monitor 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-plugin: 2020-06-03T06:39:35Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 10 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:35Z DEBUG 16384 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-port: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-localuser: 2020-06-03T06:39:35Z DEBUG dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordInHistory: 2020-06-03T06:39:35Z DEBUG 6 2020-06-03T06:39:35Z DEBUG passwordUnlock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordGraceLimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordMustChange: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:35Z DEBUG 2000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordWarning: 2020-06-03T06:39:35Z DEBUG 86400 2020-06-03T06:39:35Z DEBUG nsslapd-readonly: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:35Z DEBUG 16 2020-06-03T06:39:35Z DEBUG passwordLockout: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-localhost: 2020-06-03T06:39:35Z DEBUG replica1.ipa.test 2020-06-03T06:39:35Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:35Z DEBUG 10000 2020-06-03T06:39:35Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:35Z DEBUG 40 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordMinLength: 2020-06-03T06:39:35Z DEBUG 8 2020-06-03T06:39:35Z DEBUG passwordMinDigits: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinAlphas: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinUppers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinLowers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinSpecials: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMin8bit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinCategories: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordPalindrome: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictCheck: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictPath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordUserAttributes: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordBadWords: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordMaxSequence: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:35Z DEBUG replication-only 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 500 2020-06-03T06:39:35Z DEBUG passwordMaxFailure: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:35Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-security: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordMaxAge: 2020-06-03T06:39:35Z DEBUG 8640000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:35Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:35Z DEBUG passwordChange: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:35Z DEBUG 256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-securePort: 2020-06-03T06:39:35Z DEBUG 636 2020-06-03T06:39:35Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:35Z DEBUG 64 2020-06-03T06:39:35Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordExp: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG day 2020-06-03T06:39:35Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-nagle: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:35Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:35Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:35Z DEBUG uidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:35Z DEBUG gidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:35Z DEBUG dc=example,dc=com 2020-06-03T06:39:35Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:35Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-counters: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG passwordMinAge: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:35Z DEBUG 209715200 2020-06-03T06:39:35Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:35Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:35Z DEBUG 1048576 2020-06-03T06:39:35Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:35Z DEBUG 1024 2020-06-03T06:39:35Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:35Z DEBUG allowed 2020-06-03T06:39:35Z DEBUG nsslapd-config: 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:35Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:35Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:35Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:35Z DEBUG /tmp 2020-06-03T06:39:35Z DEBUG nsslapd-certdir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:35Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:35Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rundir: 2020-06-03T06:39:35Z DEBUG /var/run/dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:35Z DEBUG 300000 2020-06-03T06:39:35Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-localssf: 2020-06-03T06:39:35Z DEBUG 71 2020-06-03T06:39:35Z DEBUG nsslapd-minssf: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:35Z DEBUG next 2020-06-03T06:39:35Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:35Z DEBUG warn 2020-06-03T06:39:35Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:35Z DEBUG 20971520 2020-06-03T06:39:35Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:35Z DEBUG nolog 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:35Z DEBUG 128 2020-06-03T06:39:35Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:35Z DEBUG -1 2020-06-03T06:39:35Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:35Z DEBUG dirsrv-log 2020-06-03T06:39:35Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:35Z DEBUG process-safe 2020-06-03T06:39:35Z DEBUG passwordStorageScheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG passwordAdminDN: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr != aci)(version 3.0; aci "replica admins read access"; allow (read, search, compare) groupdn = "ldap:///cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || nsds50ruv || nsds5beginreplicarefresh || nsds5debugreplicatimeout || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicabindmethod || nsds5replicabusywaittime || nsds5replicachangecount || nsds5replicachangessentsincestartup || nsds5replicacleanruv || nsds5replicacleanruvnotified || nsds5replicacredentials || nsds5replicaenabled || nsds5replicahost || nsds5replicaid || nsds5replicalastinitend || nsds5replicalastinitstart || nsds5replicalastinitstatus || nsds5replicalastupdateend || nsds5replicalastupdatestart || nsds5replicalastupdatestatus || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaport || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicasessionpausetime || nsds5replicastripattrs || nsds5replicatedattributelist || nsds5replicatedattributelisttotal || nsds5replicatimeout || nsds5replicatombstonepurgeinterval || nsds5replicatransportinfo || nsds5replicatype || nsds5replicaupdateinprogress || nsds5replicaupdateschedule || nsds5task || nsds7directoryreplicasubtree || nsds7dirsynccookie || nsds7newwingroupsyncenabled || nsds7newwinusersyncenabled || nsds7windowsdomain || nsds7windowsreplicasubtree || nsruvreplicalastmodified || nsstate || objectclass || onewaysync || winsyncdirectoryfilter || winsyncinterval || winsyncmoveaction || winsyncsubtreepair || winsyncwindowsfilter")(targetfilter = "(|(objectclass=nsds5Replica)(objectclass=nsds5replicationagreement)(objectclass=nsDSWindowsReplicationAgreement)(objectClass=nsMappingTree))")(version 3.0;acl "permission:System: Read Replication Agreements";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG config 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsslapdConfig 2020-06-03T06:39:35Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:35Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-betype: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:35Z DEBUG cn=schema 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG cn=monitor 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-plugin: 2020-06-03T06:39:35Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:35Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:35Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:35Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 10 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:35Z DEBUG 16384 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-port: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-localuser: 2020-06-03T06:39:35Z DEBUG dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordInHistory: 2020-06-03T06:39:35Z DEBUG 6 2020-06-03T06:39:35Z DEBUG passwordUnlock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordGraceLimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG passwordMustChange: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:35Z DEBUG 2000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordWarning: 2020-06-03T06:39:35Z DEBUG 86400 2020-06-03T06:39:35Z DEBUG nsslapd-readonly: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:35Z DEBUG 16 2020-06-03T06:39:35Z DEBUG passwordLockout: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-localhost: 2020-06-03T06:39:35Z DEBUG replica1.ipa.test 2020-06-03T06:39:35Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:35Z DEBUG 10000 2020-06-03T06:39:35Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:35Z DEBUG 40 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG passwordMinLength: 2020-06-03T06:39:35Z DEBUG 8 2020-06-03T06:39:35Z DEBUG passwordMinDigits: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinAlphas: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinUppers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinLowers: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinSpecials: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMin8bit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMinCategories: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG passwordPalindrome: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictCheck: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordDictPath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordUserAttributes: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordBadWords: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordMaxSequence: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:35Z DEBUG replication-only 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 500 2020-06-03T06:39:35Z DEBUG passwordMaxFailure: 2020-06-03T06:39:35Z DEBUG 3 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:35Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-security: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordMaxAge: 2020-06-03T06:39:35Z DEBUG 8640000 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:35Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:35Z DEBUG passwordChange: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:35Z DEBUG 256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-securePort: 2020-06-03T06:39:35Z DEBUG 636 2020-06-03T06:39:35Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:35Z DEBUG 64 2020-06-03T06:39:35Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG passwordExp: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG day 2020-06-03T06:39:35Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:35Z DEBUG 3600 2020-06-03T06:39:35Z DEBUG nsslapd-nagle: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:35Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:35Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:35Z DEBUG uidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:35Z DEBUG gidNumber 2020-06-03T06:39:35Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:35Z DEBUG dc=example,dc=com 2020-06-03T06:39:35Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:35Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-counters: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:35Z DEBUG cn=Directory Manager 2020-06-03T06:39:35Z DEBUG passwordMinAge: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:35Z DEBUG 209715200 2020-06-03T06:39:35Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:35Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:35Z DEBUG 1048576 2020-06-03T06:39:35Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:35Z DEBUG 1024 2020-06-03T06:39:35Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:35Z DEBUG allowed 2020-06-03T06:39:35Z DEBUG nsslapd-config: 2020-06-03T06:39:35Z DEBUG cn=config 2020-06-03T06:39:35Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:35Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:35Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:35Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:35Z DEBUG /tmp 2020-06-03T06:39:35Z DEBUG nsslapd-certdir: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:35Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:35Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:35Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:35Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rundir: 2020-06-03T06:39:35Z DEBUG /var/run/dirsrv 2020-06-03T06:39:35Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:35Z DEBUG 300000 2020-06-03T06:39:35Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-localssf: 2020-06-03T06:39:35Z DEBUG 71 2020-06-03T06:39:35Z DEBUG nsslapd-minssf: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:35Z DEBUG next 2020-06-03T06:39:35Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:35Z DEBUG warn 2020-06-03T06:39:35Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:35Z DEBUG 20971520 2020-06-03T06:39:35Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:35Z DEBUG nolog 2020-06-03T06:39:35Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:35Z DEBUG 2097152 2020-06-03T06:39:35Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:35Z DEBUG 128 2020-06-03T06:39:35Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:35Z DEBUG -10 2020-06-03T06:39:35Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:35Z DEBUG -1 2020-06-03T06:39:35Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:35Z DEBUG 600 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:35Z DEBUG 100 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:35Z DEBUG 1 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:35Z DEBUG 2 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:35Z DEBUG month 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:35Z DEBUG 5 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:35Z DEBUG week 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:35Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:35Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:35Z DEBUG dirsrv-log 2020-06-03T06:39:35Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:35Z DEBUG none 2020-06-03T06:39:35Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:35Z DEBUG process-safe 2020-06-03T06:39:35Z DEBUG passwordStorageScheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG passwordAdminDN: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:35Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:35Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:35Z DEBUG off 2020-06-03T06:39:35Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:35Z DEBUG 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=ipa,dc=test")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,cn=roles,cn=accounts,dc=ipa,dc=test")(version 3.0; acl "No anonymous access to roles"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "memberOf || memberHost || memberUser")(version 3.0; acl "No anonymous access to member information"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=ipa,dc=test")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "*")(target = "ldap:///cn=*,ou=SUDOers,dc=ipa,dc=test")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG hbac 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value ['(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to hbac"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG hbac 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Add HBAC Rule";allow (add) groupdn = "ldap:///cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Delete HBAC Rule";allow (delete) groupdn = "ldap:///cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "externalhost || memberhost || memberservice || memberuser")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Manage HBAC Rule Membership";allow (write) groupdn = "ldap:///cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "accessruletype || accesstime || cn || description || hostcategory || ipaenabledflag || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Modify HBAC Rule";allow (write) groupdn = "ldap:///cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "accessruletype || accesstime || cn || createtimestamp || description || entryusn || externalhost || hostcategory || ipaenabledflag || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || sourcehost || sourcehostcategory || usercategory")(targetfilter = "(objectclass=ipahbacrule)")(version 3.0;acl "permission:System: Read HBAC Rules";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=sudo,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=sudo,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG sudo 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' from aci, current value [] 2020-06-03T06:39:35Z DEBUG remove: '(targetattr = "*")(version 3.0; acl "No anonymous access to sudo"; deny (read,search,compare) userdn != "ldap:///all";)' not in aci 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=sudo,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG sudo 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG accounts 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)' to aci, current value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG accounts 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policy"; allow (write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "Admins can manage delegations"; allow (write, delete) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Users allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Groups allowed to retrieve keytab keys"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Users allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Groups allowed to create keytab keys"; allow(write) userattr="ipaAllowedToPerform;write_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey themselves"; allow(write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Admins are allowed to rekey any entity"; allow(write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(|(objectclass=ipaHost)(objectclass=ipaService))")(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Entities are allowed to rekey managed entries"; allow(write) userattr="managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG associatedDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG nisDomain: 2020-06-03T06:39:35Z DEBUG ipa.test 2020-06-03T06:39:35Z DEBUG info: 2020-06-03T06:39:35Z DEBUG IPA V2.0 2020-06-03T06:39:35Z DEBUG dc: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG domain 2020-06-03T06:39:35Z DEBUG pilotObject 2020-06-03T06:39:35Z DEBUG domainRelatedObject 2020-06-03T06:39:35Z DEBUG nisDomainObject 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG groups 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Add Groups";allow (add) groupdn = "ldap:///cn=System: Add Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaexternalmember")(targetfilter = "(objectclass=ipaexternalgroup)")(version 3.0;acl "permission:System: Modify External Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(&(!(cn=admins))(objectclass=ipausergroup))")(version 3.0;acl "permission:System: Modify Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || gidnumber || ipauniqueid || membermanager || mepmanagedby || objectclass")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Modify Groups";allow (write) groupdn = "ldap:///cn=System: Modify Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaexternalmember")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read External Group Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member || memberhost || memberof || memberuid || memberuser")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Group Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "businesscategory || cn || createtimestamp || description || entryusn || gidnumber || ipaexternalmember || ipantsecurityidentifier || ipauniqueid || membermanager || mepmanagedby || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Groups";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Remove Groups";allow (delete) groupdn = "ldap:///cn=System: Remove Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=ipausers,cn=groups,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add User to default group";allow (write) groupdn = "ldap:///cn=System: Add User to default group,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)' to aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)', '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)', '(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Add Groups";allow (add) groupdn = "ldap:///cn=System: Add Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaexternalmember")(targetfilter = "(objectclass=ipaexternalgroup)")(version 3.0;acl "permission:System: Modify External Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(targetfilter = "(&(!(cn=admins))(objectclass=ipausergroup))")(version 3.0;acl "permission:System: Modify Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || gidnumber || ipauniqueid || membermanager || mepmanagedby || objectclass")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Modify Groups";allow (write) groupdn = "ldap:///cn=System: Modify Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaexternalmember")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read External Group Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "member || memberhost || memberof || memberuid || memberuser")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Group Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || gidnumber || ipaexternalmember || ipantsecurityidentifier || ipauniqueid || membermanager || mepmanagedby || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Groups";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Remove Groups";allow (delete) groupdn = "ldap:///cn=System: Remove Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=ipausers,cn=groups,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add User to default group";allow (write) groupdn = "ldap:///cn=System: Add User to default group,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)', '(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Add Groups";allow (add) groupdn = "ldap:///cn=System: Add Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaexternalmember")(targetfilter = "(objectclass=ipaexternalgroup)")(version 3.0;acl "permission:System: Modify External Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(targetfilter = "(&(!(cn=admins))(objectclass=ipausergroup))")(version 3.0;acl "permission:System: Modify Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || gidnumber || ipauniqueid || membermanager || mepmanagedby || objectclass")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Modify Groups";allow (write) groupdn = "ldap:///cn=System: Modify Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaexternalmember")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read External Group Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "member || memberhost || memberof || memberuid || memberuser")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Group Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || gidnumber || ipaexternalmember || ipantsecurityidentifier || ipauniqueid || membermanager || mepmanagedby || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Groups";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Remove Groups";allow (delete) groupdn = "ldap:///cn=System: Remove Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=ipausers,cn=groups,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add User to default group";allow (write) groupdn = "ldap:///cn=System: Add User to default group,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG groups 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Add Groups";allow (add) groupdn = "ldap:///cn=System: Add Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaexternalmember")(targetfilter = "(objectclass=ipaexternalgroup)")(version 3.0;acl "permission:System: Modify External Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(&(!(cn=admins))(objectclass=ipausergroup))")(version 3.0;acl "permission:System: Modify Group Membership";allow (write) groupdn = "ldap:///cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || gidnumber || ipauniqueid || membermanager || mepmanagedby || objectclass")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Modify Groups";allow (write) groupdn = "ldap:///cn=System: Modify Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "ipaexternalmember")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read External Group Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member || memberhost || memberof || memberuid || memberuser")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Group Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "businesscategory || cn || createtimestamp || description || entryusn || gidnumber || ipaexternalmember || ipantsecurityidentifier || ipauniqueid || membermanager || mepmanagedby || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Read Groups";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(|(objectclass=ipausergroup)(objectclass=posixgroup))")(version 3.0;acl "permission:System: Remove Groups";allow (delete) groupdn = "ldap:///cn=System: Remove Groups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(target = "ldap:///cn=ipausers,cn=groups,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add User to default group";allow (write) groupdn = "ldap:///cn=System: Add User to default group,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaUserGroup)")(version 3.0; acl "Allow member managers to modify members of user groups"; allow (write) userattr = "memberManager#USERDN";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG hostgroups 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Add Hostgroups";allow (add) groupdn = "ldap:///cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(&(!(cn=ipaservers))(objectclass=ipahostgroup))")(version 3.0;acl "permission:System: Modify Hostgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || membermanager")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Modify Hostgroups";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || membermanager || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroups";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Remove Hostgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)' to aci, current value ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)', '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)', '(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Add Hostgroups";allow (add) groupdn = "ldap:///cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(targetfilter = "(&(!(cn=ipaservers))(objectclass=ipahostgroup))")(version 3.0;acl "permission:System: Modify Hostgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || membermanager")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Modify Hostgroups";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || membermanager || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroups";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Remove Hostgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";)', '(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Add Hostgroups";allow (add) groupdn = "ldap:///cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(targetfilter = "(&(!(cn=ipaservers))(objectclass=ipahostgroup))")(version 3.0;acl "permission:System: Modify Hostgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || membermanager")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Modify Hostgroups";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroup Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || membermanager || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroups";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Remove Hostgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG hostgroups 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN" or userattr = "memberManager#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Add Hostgroups";allow (add) groupdn = "ldap:///cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(&(!(cn=ipaservers))(objectclass=ipahostgroup))")(version 3.0;acl "permission:System: Modify Hostgroup Membership";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || description || membermanager")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Modify Hostgroups";allow (write) groupdn = "ldap:///cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member || memberhost || memberof || memberuser")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroup Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "businesscategory || cn || createtimestamp || description || entryusn || ipauniqueid || membermanager || modifytimestamp || o || objectclass || ou || owner || seealso")(targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Read Hostgroups";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipahostgroup)")(version 3.0;acl "permission:System: Remove Hostgroups";allow (delete) groupdn = "ldap:///cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "member")(targetfilter = "(objectclass=ipaHostGroup)")(version 3.0; acl "Allow member managers to modify members of host groups"; allow (write) userattr = "memberManager#USERDN";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG services 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";) 2020-06-03T06:39:35Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG remove: '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaKrbPrincipal)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG services 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:35Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";) 2020-06-03T06:39:35Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ranges,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ranges 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)' to aci, current value ['(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";)', '(target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ranges,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ranges 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG sysaccounts 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG sysaccounts 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "objectClass || cn")(version 3.0; acl "Allow hosts to read replication managers"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test")(targetattr = "member")(version 3.0; acl "IPA server hosts can modify replication managers members"; allow(read, search, compare, write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG etc 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication,cn=etc,dc=ipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=replication,cn=etc,dc=ipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=replication,cn=etc,dc=ipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";)', '(target = "ldap:///cn=replication,cn=etc,dc=ipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG etc 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(objectClass=ipaGuiConfig)")(targetattr != "aci")(version 3.0;acl "Admins can change GUI config"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantdomainguid || ipantfallbackprimarygroup || ipantflatname || ipantsecurityidentifier || modifytimestamp || objectclass")(target = "ldap:///cn=ad,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectclass=ipantdomainattrs)")(version 3.0;acl "permission:System: Read AD Domains";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=replication,cn=etc,dc=ipa,dc=test")(targetattr = "nsDS5ReplicaId")(version 3.0; acl "IPA server hosts can change replica ID"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: krbPrincipalName=WELLKNOWN/ANONYMOUS@IPA.TEST,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@IPA.TEST,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG ipaAllowedToPerform;read_keys: 2020-06-03T06:39:35Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbExtraData: 2020-06-03T06:39:35Z DEBUG AAK6Qtdecm9vdC9hZG1pbkBJUEEuVEVTVAA= 2020-06-03T06:39:35Z DEBUG krbPrincipalKey: 2020-06-03T06:39:35Z DEBUG XXXXXXXX 2020-06-03T06:39:35Z DEBUG krbLastPwdChange: 2020-06-03T06:39:35Z DEBUG 20200603062706Z 2020-06-03T06:39:35Z DEBUG krbCanonicalName: 2020-06-03T06:39:35Z DEBUG WELLKNOWN/ANONYMOUS@IPA.TEST 2020-06-03T06:39:35Z DEBUG krbPrincipalName: 2020-06-03T06:39:35Z DEBUG WELLKNOWN/ANONYMOUS@IPA.TEST 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbprincipal 2020-06-03T06:39:35Z DEBUG krbprincipalaux 2020-06-03T06:39:35Z DEBUG krbTicketPolicyAux 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG ipaAllowedOperations 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:35Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG addifexist: 'ipaAllowedOperations' to objectclass, current value ['krbprincipal', 'krbprincipalaux', 'krbTicketPolicyAux', 'top', 'ipaAllowedOperations'] 2020-06-03T06:39:35Z DEBUG addifexist: set objectclass to ['krbprincipal', 'krbprincipalaux', 'krbTicketPolicyAux', 'top', 'ipaAllowedOperations', 'ipaAllowedOperations'] 2020-06-03T06:39:35Z DEBUG addifexist: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-03T06:39:35Z DEBUG addifexist: set aci to ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-03T06:39:35Z DEBUG addifexist: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test' to ipaAllowedToPerform;read_keys, current value ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG addifexist: set ipaAllowedToPerform;read_keys to ['cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: krbPrincipalName=WELLKNOWN/ANONYMOUS@IPA.TEST,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG ipaAllowedToPerform;read_keys: 2020-06-03T06:39:35Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbExtraData: 2020-06-03T06:39:35Z DEBUG AAK6Qtdecm9vdC9hZG1pbkBJUEEuVEVTVAA= 2020-06-03T06:39:35Z DEBUG krbPrincipalKey: 2020-06-03T06:39:35Z DEBUG XXXXXXXX 2020-06-03T06:39:35Z DEBUG krbLastPwdChange: 2020-06-03T06:39:35Z DEBUG 20200603062706Z 2020-06-03T06:39:35Z DEBUG krbCanonicalName: 2020-06-03T06:39:35Z DEBUG WELLKNOWN/ANONYMOUS@IPA.TEST 2020-06-03T06:39:35Z DEBUG krbPrincipalName: 2020-06-03T06:39:35Z DEBUG WELLKNOWN/ANONYMOUS@IPA.TEST 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbprincipal 2020-06-03T06:39:35Z DEBUG krbprincipalaux 2020-06-03T06:39:35Z DEBUG krbTicketPolicyAux 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG ipaAllowedOperations 2020-06-03T06:39:35Z DEBUG ipaAllowedOperations 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:35Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG aci: 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow to retrieve keytab keys of the anonymous user"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-aci.update 0.208 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/20-default_password_policy.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdLockoutDuration: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdFailureCountInterval: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMaxFailure: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMaxPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdHistoryLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinDiffChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMinPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Host Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbPwdPolicy 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdLockoutDuration: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdFailureCountInterval: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMaxFailure: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMaxPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdHistoryLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinDiffChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMinPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Host Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbPwdPolicy 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Default Service Password Policy,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdLockoutDuration: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdFailureCountInterval: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMaxFailure: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMaxPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdHistoryLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinDiffChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMinPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Service Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbPwdPolicy 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Default Service Password Policy,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdLockoutDuration: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdFailureCountInterval: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMaxFailure: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMaxPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdHistoryLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinDiffChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMinPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Service Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbPwdPolicy 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Kerberos Service Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Kerberos Service Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdLockoutDuration: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdFailureCountInterval: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMaxFailure: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMaxPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdHistoryLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinDiffChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMinPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Kerberos Service Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbPwdPolicy 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdLockoutDuration: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdFailureCountInterval: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMaxFailure: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMaxPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdHistoryLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinLength: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbPwdMinDiffChars: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG krbMinPwdLife: 2020-06-03T06:39:35Z DEBUG 0 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Kerberos Service Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG krbPwdPolicy 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=cosTemplates,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG cosTemplates 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=cosTemplates,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG cosTemplates 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:35Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cosPriority: 2020-06-03T06:39:35Z DEBUG 10000000000 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG cosTemplate 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG krbContainer 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:35Z DEBUG cn=Default Host Password Policy,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cosPriority: 2020-06-03T06:39:35Z DEBUG 10000000000 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG cosTemplate 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG krbContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Default Password Policy,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG cosAttribute: 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference default 2020-06-03T06:39:35Z DEBUG costemplatedn: 2020-06-03T06:39:35Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG ldapsubentry 2020-06-03T06:39:35Z DEBUG cosSuperDefinition 2020-06-03T06:39:35Z DEBUG cosPointerDefinition 2020-06-03T06:39:35Z DEBUG description: 2020-06-03T06:39:35Z DEBUG Default Password Policy for Hosts 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG cosAttribute: 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference default 2020-06-03T06:39:35Z DEBUG costemplatedn: 2020-06-03T06:39:35Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG ldapsubentry 2020-06-03T06:39:35Z DEBUG cosSuperDefinition 2020-06-03T06:39:35Z DEBUG cosPointerDefinition 2020-06-03T06:39:35Z DEBUG description: 2020-06-03T06:39:35Z DEBUG Default Password Policy for Hosts 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=cosTemplates,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG cosTemplates 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=cosTemplates,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG cosTemplates 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:35Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cosPriority: 2020-06-03T06:39:35Z DEBUG 10000000000 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG cosTemplate 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG krbContainer 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:35Z DEBUG cn=Default Service Password Policy,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cosPriority: 2020-06-03T06:39:35Z DEBUG 10000000000 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG cosTemplate 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG krbContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Default Password Policy,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG cosAttribute: 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference default 2020-06-03T06:39:35Z DEBUG costemplatedn: 2020-06-03T06:39:35Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG ldapsubentry 2020-06-03T06:39:35Z DEBUG cosSuperDefinition 2020-06-03T06:39:35Z DEBUG cosPointerDefinition 2020-06-03T06:39:35Z DEBUG description: 2020-06-03T06:39:35Z DEBUG Default Password Policy for Services 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG cosAttribute: 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference default 2020-06-03T06:39:35Z DEBUG costemplatedn: 2020-06-03T06:39:35Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG ldapsubentry 2020-06-03T06:39:35Z DEBUG cosSuperDefinition 2020-06-03T06:39:35Z DEBUG cosPointerDefinition 2020-06-03T06:39:35Z DEBUG description: 2020-06-03T06:39:35Z DEBUG Default Password Policy for Services 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=cosTemplates,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=cosTemplates,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG cosTemplates 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=cosTemplates,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG cosTemplates 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Default Password Policy,cn=cosTemplates,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:35Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cosPriority: 2020-06-03T06:39:35Z DEBUG 10000000000 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG cosTemplate 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG krbContainer 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=cosTemplates,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:35Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cosPriority: 2020-06-03T06:39:35Z DEBUG 10000000000 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG cosTemplate 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG krbContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Default Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG cosAttribute: 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference default 2020-06-03T06:39:35Z DEBUG costemplatedn: 2020-06-03T06:39:35Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG ldapsubentry 2020-06-03T06:39:35Z DEBUG cosSuperDefinition 2020-06-03T06:39:35Z DEBUG cosPointerDefinition 2020-06-03T06:39:35Z DEBUG description: 2020-06-03T06:39:35Z DEBUG Default Password Policy for Kerberos Services 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Default Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Default Password Policy 2020-06-03T06:39:35Z DEBUG cosAttribute: 2020-06-03T06:39:35Z DEBUG krbPwdPolicyReference default 2020-06-03T06:39:35Z DEBUG costemplatedn: 2020-06-03T06:39:35Z DEBUG cn=Default Password Policy,cn=cosTemplates,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG ldapsubentry 2020-06-03T06:39:35Z DEBUG cosSuperDefinition 2020-06-03T06:39:35Z DEBUG cosPointerDefinition 2020-06-03T06:39:35Z DEBUG description: 2020-06-03T06:39:35Z DEBUG Default Password Policy for Kerberos Services 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-default_password_policy.update 0.030 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/20-dna.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ipa-winsync,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa-winsync 2020-06-03T06:39:35Z DEBUG ipawinsyncacctdisable: 2020-06-03T06:39:35Z DEBUG both 2020-06-03T06:39:35Z DEBUG ipawinsyncdefaultgroupattr: 2020-06-03T06:39:35Z DEBUG ipaDefaultPrimaryGroup 2020-06-03T06:39:35Z DEBUG ipawinsyncdefaultgroupfilter: 2020-06-03T06:39:35Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2020-06-03T06:39:35Z DEBUG ipawinsyncforcesync: 2020-06-03T06:39:35Z DEBUG true 2020-06-03T06:39:35Z DEBUG ipawinsynchomedirattr: 2020-06-03T06:39:35Z DEBUG ipaHomesRootDir 2020-06-03T06:39:35Z DEBUG ipawinsyncloginshellattr: 2020-06-03T06:39:35Z DEBUG ipaDefaultLoginShell 2020-06-03T06:39:35Z DEBUG ipawinsyncnewentryfilter: 2020-06-03T06:39:35Z DEBUG (cn=ipaConfig) 2020-06-03T06:39:35Z DEBUG ipawinsyncnewuserocattr: 2020-06-03T06:39:35Z DEBUG ipauserobjectclasses 2020-06-03T06:39:35Z DEBUG ipawinsyncrealmattr: 2020-06-03T06:39:35Z DEBUG cn 2020-06-03T06:39:35Z DEBUG ipawinsyncrealmfilter: 2020-06-03T06:39:35Z DEBUG (objectclass=krbRealmContainer) 2020-06-03T06:39:35Z DEBUG ipawinsyncuserattr: 2020-06-03T06:39:35Z DEBUG uidNumber -1 2020-06-03T06:39:35Z DEBUG gidNumber -1 2020-06-03T06:39:35Z DEBUG ipawinsyncuserflatten: 2020-06-03T06:39:35Z DEBUG true 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG ipa winsync plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG ipa-winsync-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG ipa_winsync_plugin_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libipa_winsync 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG FreeIPA project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG FreeIPA/1.0 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG remove: 'uidNumber 999' from ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2020-06-03T06:39:35Z DEBUG remove: 'uidNumber 999' not in ipaWinSyncUserAttr 2020-06-03T06:39:35Z DEBUG remove: 'gidNumber 999' from ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2020-06-03T06:39:35Z DEBUG remove: 'gidNumber 999' not in ipaWinSyncUserAttr 2020-06-03T06:39:35Z DEBUG add: 'uidNumber -1' to ipaWinSyncUserAttr, current value ['uidNumber -1', 'gidNumber -1'] 2020-06-03T06:39:35Z DEBUG add: updated value ['gidNumber -1', 'uidNumber -1'] 2020-06-03T06:39:35Z DEBUG add: 'gidNumber -1' to ipaWinSyncUserAttr, current value ['gidNumber -1', 'uidNumber -1'] 2020-06-03T06:39:35Z DEBUG add: updated value ['uidNumber -1', 'gidNumber -1'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ipa-winsync,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipa-winsync 2020-06-03T06:39:35Z DEBUG ipawinsyncacctdisable: 2020-06-03T06:39:35Z DEBUG both 2020-06-03T06:39:35Z DEBUG ipawinsyncdefaultgroupattr: 2020-06-03T06:39:35Z DEBUG ipaDefaultPrimaryGroup 2020-06-03T06:39:35Z DEBUG ipawinsyncdefaultgroupfilter: 2020-06-03T06:39:35Z DEBUG (gidNumber=*)(objectclass=posixGroup)(objectclass=groupOfNames) 2020-06-03T06:39:35Z DEBUG ipawinsyncforcesync: 2020-06-03T06:39:35Z DEBUG true 2020-06-03T06:39:35Z DEBUG ipawinsynchomedirattr: 2020-06-03T06:39:35Z DEBUG ipaHomesRootDir 2020-06-03T06:39:35Z DEBUG ipawinsyncloginshellattr: 2020-06-03T06:39:35Z DEBUG ipaDefaultLoginShell 2020-06-03T06:39:35Z DEBUG ipawinsyncnewentryfilter: 2020-06-03T06:39:35Z DEBUG (cn=ipaConfig) 2020-06-03T06:39:35Z DEBUG ipawinsyncnewuserocattr: 2020-06-03T06:39:35Z DEBUG ipauserobjectclasses 2020-06-03T06:39:35Z DEBUG ipawinsyncrealmattr: 2020-06-03T06:39:35Z DEBUG cn 2020-06-03T06:39:35Z DEBUG ipawinsyncrealmfilter: 2020-06-03T06:39:35Z DEBUG (objectclass=krbRealmContainer) 2020-06-03T06:39:35Z DEBUG ipawinsyncuserattr: 2020-06-03T06:39:35Z DEBUG uidNumber -1 2020-06-03T06:39:35Z DEBUG gidNumber -1 2020-06-03T06:39:35Z DEBUG ipawinsyncuserflatten: 2020-06-03T06:39:35Z DEBUG true 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG ipa winsync plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG ipa-winsync-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG ipa_winsync_plugin_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libipa_winsync 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG FreeIPA project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG FreeIPA/1.0 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:35Z DEBUG 60 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-dna.update 0.006 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/20-enable_dirsrv_plugins.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG 7-bit check 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce 7-bit clean attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NS7bitAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NS7bitAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg0: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg1: 2020-06-03T06:39:35Z DEBUG mail 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg2: 2020-06-03T06:39:35Z DEBUG , 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg3: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG 7-bit check 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Enforce 7-bit clean attribute values 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG NS7bitAttr 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG NS7bitAttr_Init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libattr-unique-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg0: 2020-06-03T06:39:35Z DEBUG uid 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg1: 2020-06-03T06:39:35Z DEBUG mail 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg2: 2020-06-03T06:39:35Z DEBUG , 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg3: 2020-06-03T06:39:35Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Account Usability Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Account Usability Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Account Usability Control plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Account Usability Control 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG auc_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libacctusability-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Account Usability Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Account Usability Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Account Usability Control plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Account Usability Control 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG auc_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libacctusability-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ACL Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ACL Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG acl access check plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG acl 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG acl_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libacl-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG accesscontrol 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ACL Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ACL Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG acl access check plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG acl 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG acl_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libacl-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG accesscontrol 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ACL preoperation,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ACL preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG acl access check plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG acl 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG acl_preopInit 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libacl-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ACL preoperation,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ACL preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG acl access check plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG acl 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG acl_preopInit 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libacl-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG automemberprocessmodifyops: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Auto Membership Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Auto Membership plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Auto Membership 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG automember_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libautomember-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG automemberprocessmodifyops: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Auto Membership Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Auto Membership plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Auto Membership 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG automember_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libautomember-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Bitwise Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Bitwise Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG bitwise match plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG bitwise 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG bitwise_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libbitwise-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG matchingRule 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Bitwise Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Bitwise Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG bitwise match plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG bitwise 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG bitwise_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libbitwise-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG matchingRule 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=chaining database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG chaining database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG LDAP chaining backend database plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG chaining database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG chaining_back_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libchainingdb-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=chaining database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG chaining database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG LDAP chaining backend database plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG chaining database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG chaining_back_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libchainingdb-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Class of Service,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Class of Service 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG Views 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG class of service plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG cos 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG cos_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libcos-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Class of Service,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Class of Service 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG Views 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG class of service plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG cos 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG cos_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libcos-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=deref,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=deref,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG deref 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Dereference plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Dereference 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG deref_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libderef-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=deref,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG deref 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Dereference plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Dereference 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG deref_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libderef-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=HTTP Client,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG HTTP Client 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG HTTP Client plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG http-client 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG http_client_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libhttp-client-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=HTTP Client,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG HTTP Client 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG HTTP Client plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG http-client 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG http_client_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libhttp-client-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG preoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Internationalization Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Internationalization Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG internationalized ordering rule plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG orderingrule 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG orderingRule_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libcollation-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG matchingRule 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg0: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST/slapd-collations.conf 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Internationalization Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Internationalization Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG internationalized ordering rule plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG orderingrule 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG orderingRule_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libcollation-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG matchingRule 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginarg0: 2020-06-03T06:39:35Z DEBUG /etc/dirsrv/slapd-IPA-TEST/slapd-collations.conf 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Linked Attributes,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Linked Attributes 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Linked Attributes plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Linked Attributes 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG linked_attrs_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG liblinkedattrs-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Linked Attributes,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Linked Attributes 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Linked Attributes plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Linked Attributes 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG linked_attrs_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG liblinkedattrs-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Managed Entries,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Managed Entries plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG mep_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libmanagedentries-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Managed Entries,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:35Z DEBUG cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Managed Entries plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG Managed Entries 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG mep_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libmanagedentries-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpreoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG nsContainer 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Multimaster Replication Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG AES 2020-06-03T06:39:35Z DEBUG Class of Service 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Multi-master Replication Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG replication-multimaster 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG replication_multimaster_plugin_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libreplication-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Multimaster Replication Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Multimaster Replication Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG ldbm database 2020-06-03T06:39:35Z DEBUG AES 2020-06-03T06:39:35Z DEBUG Class of Service 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG Multi-master Replication Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG replication-multimaster 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG replication_multimaster_plugin_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libreplication-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Roles Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Roles Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG Views 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG roles plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG roles 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG roles_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libroles-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Roles Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Roles Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG Views 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG roles plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG roles 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG roles_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libroles-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Schema Reload,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Schema Reload 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG task plugin to reload schema files 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG schemareload 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG schemareload_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libschemareload-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Schema Reload,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Schema Reload 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG task plugin to reload schema files 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG schemareload 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG schemareload_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libschemareload-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=State Change Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG state change notification service plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG statechange 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG statechange_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libstatechange-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=State Change Plugin,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG state change notification service plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG statechange 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG statechange_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libstatechange-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG betxnpostoperation 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=Views,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=Views,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Views 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG virtual directory information tree views plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG views 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG views_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libviews-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=Views,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG Views 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:35Z DEBUG State Change Plugin 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG virtual directory information tree views plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG views 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG views_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libviews-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG object 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG whoami 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG whoami extended operation plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG whoami-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG whoami_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libwhoami-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG extendedop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG replace: off not found, skipping 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG whoami 2020-06-03T06:39:35Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:35Z DEBUG database 2020-06-03T06:39:35Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:35Z DEBUG whoami extended operation plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:35Z DEBUG on 2020-06-03T06:39:35Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:35Z DEBUG whoami-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:35Z DEBUG whoami_init 2020-06-03T06:39:35Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:35Z DEBUG libwhoami-plugin 2020-06-03T06:39:35Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:35Z DEBUG extendedop 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:35Z DEBUG 389 Project 2020-06-03T06:39:35Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:35Z DEBUG 1.4.1.18 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsSlapdPlugin 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-enable_dirsrv_plugins.update 0.065 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/20-host_nis_groups.update' 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG mepMappedAttr: 2020-06-03T06:39:35Z DEBUG cn: $cn 2020-06-03T06:39:35Z DEBUG memberHost: $dn 2020-06-03T06:39:35Z DEBUG description: ipaNetgroup $cn 2020-06-03T06:39:35Z DEBUG mepStaticAttr: 2020-06-03T06:39:35Z DEBUG ipaUniqueId: autogenerate 2020-06-03T06:39:35Z DEBUG objectclass: ipanisnetgroup 2020-06-03T06:39:35Z DEBUG objectclass: ipaobject 2020-06-03T06:39:35Z DEBUG nisDomainName: ipa.test 2020-06-03T06:39:35Z DEBUG mepRDNAttr: 2020-06-03T06:39:35Z DEBUG cn 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG NGP HGP Template 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG mepTemplateEntry 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG mepMappedAttr: 2020-06-03T06:39:35Z DEBUG cn: $cn 2020-06-03T06:39:35Z DEBUG memberHost: $dn 2020-06-03T06:39:35Z DEBUG description: ipaNetgroup $cn 2020-06-03T06:39:35Z DEBUG mepStaticAttr: 2020-06-03T06:39:35Z DEBUG ipaUniqueId: autogenerate 2020-06-03T06:39:35Z DEBUG objectclass: ipanisnetgroup 2020-06-03T06:39:35Z DEBUG objectclass: ipaobject 2020-06-03T06:39:35Z DEBUG nisDomainName: ipa.test 2020-06-03T06:39:35Z DEBUG mepRDNAttr: 2020-06-03T06:39:35Z DEBUG cn 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG NGP HGP Template 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG mepTemplateEntry 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG managedTemplate: 2020-06-03T06:39:35Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG managedBase: 2020-06-03T06:39:35Z DEBUG cn=ng,cn=alt,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG originFilter: 2020-06-03T06:39:35Z DEBUG objectclass=ipahostgroup 2020-06-03T06:39:35Z DEBUG originScope: 2020-06-03T06:39:35Z DEBUG cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG NGP Definition 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG only: set cn to 'NGP Definition', current value ['NGP Definition'] 2020-06-03T06:39:35Z DEBUG only: updated value ['NGP Definition'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=NGP Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG managedTemplate: 2020-06-03T06:39:35Z DEBUG cn=NGP HGP Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG managedBase: 2020-06-03T06:39:35Z DEBUG cn=ng,cn=alt,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG originFilter: 2020-06-03T06:39:35Z DEBUG objectclass=ipahostgroup 2020-06-03T06:39:35Z DEBUG originScope: 2020-06-03T06:39:35Z DEBUG cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG NGP Definition 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG extensibleObject 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:35Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-host_nis_groups.update 0.005 sec 2020-06-03T06:39:35Z DEBUG Parsing update file '/usr/share/ipa/updates/20-idoverride_index.update' 2020-06-03T06:39:35Z DEBUG New entry: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipaOriginalUid 2020-06-03T06:39:35Z DEBUG ObjectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsIndex 2020-06-03T06:39:35Z DEBUG nsSystemIndex: 2020-06-03T06:39:35Z DEBUG false 2020-06-03T06:39:35Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-03T06:39:35Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:35Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:35Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ipaOriginalUid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipaOriginalUid 2020-06-03T06:39:35Z DEBUG ObjectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsIndex 2020-06-03T06:39:35Z DEBUG nsSystemIndex: 2020-06-03T06:39:35Z DEBUG false 2020-06-03T06:39:35Z DEBUG nsIndexType: 2020-06-03T06:39:35Z DEBUG eq 2020-06-03T06:39:35Z DEBUG pres 2020-06-03T06:39:35Z DEBUG New entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipaAnchorUUID 2020-06-03T06:39:35Z DEBUG ObjectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsIndex 2020-06-03T06:39:35Z DEBUG nsSystemIndex: 2020-06-03T06:39:35Z DEBUG false 2020-06-03T06:39:35Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-03T06:39:35Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:35Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:35Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipaAnchorUUID 2020-06-03T06:39:35Z DEBUG ObjectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsIndex 2020-06-03T06:39:35Z DEBUG nsSystemIndex: 2020-06-03T06:39:35Z DEBUG false 2020-06-03T06:39:35Z DEBUG nsIndexType: 2020-06-03T06:39:35Z DEBUG eq 2020-06-03T06:39:35Z DEBUG pres 2020-06-03T06:39:35Z DEBUG Updating existing entry: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Initial value 2020-06-03T06:39:35Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipaAnchorUUID 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsIndex 2020-06-03T06:39:35Z DEBUG nsSystemIndex: 2020-06-03T06:39:35Z DEBUG false 2020-06-03T06:39:35Z DEBUG nsIndexType: 2020-06-03T06:39:35Z DEBUG eq 2020-06-03T06:39:35Z DEBUG pres 2020-06-03T06:39:35Z DEBUG remove: 'ipaOriginalUid' from cn, current value ['ipaAnchorUUID'] 2020-06-03T06:39:35Z DEBUG remove: 'ipaOriginalUid' not in cn 2020-06-03T06:39:35Z DEBUG --------------------------------------------- 2020-06-03T06:39:35Z DEBUG Final value after applying updates 2020-06-03T06:39:35Z DEBUG dn: cn=ipaAnchorUUID,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:35Z DEBUG cn: 2020-06-03T06:39:35Z DEBUG ipaAnchorUUID 2020-06-03T06:39:35Z DEBUG objectClass: 2020-06-03T06:39:35Z DEBUG top 2020-06-03T06:39:35Z DEBUG nsIndex 2020-06-03T06:39:35Z DEBUG nsSystemIndex: 2020-06-03T06:39:35Z DEBUG false 2020-06-03T06:39:35Z DEBUG nsIndexType: 2020-06-03T06:39:35Z DEBUG eq 2020-06-03T06:39:35Z DEBUG pres 2020-06-03T06:39:35Z DEBUG [] 2020-06-03T06:39:35Z DEBUG Updated 0 2020-06-03T06:39:35Z DEBUG Done 2020-06-03T06:39:40Z DEBUG Creating task cn=indextask_138104591806630880_8522,cn=index,cn=tasks,cn=config to index attributes: ipaAnchorUUID, ipaOriginalUid 2020-06-03T06:39:41Z DEBUG Indexing finished 2020-06-03T06:39:41Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-idoverride_index.update 6.050 sec 2020-06-03T06:39:41Z DEBUG Parsing update file '/usr/share/ipa/updates/20-indices.update' 2020-06-03T06:39:41Z DEBUG New entry: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberuid 2020-06-03T06:39:41Z DEBUG ObjectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=memberuid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberuid 2020-06-03T06:39:41Z DEBUG ObjectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberHost 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=memberHost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberHost 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberUser 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=memberUser,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberUser 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG member 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=member,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG member 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [(0, 'nsIndexType', ['pres', 'sub'])] 2020-06-03T06:39:41Z DEBUG Updated 1 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG uniquemember 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=uniquemember,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG uniquemember 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [(0, 'nsIndexType', ['sub'])] 2020-06-03T06:39:41Z DEBUG Updated 1 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG owner 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=owner,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG owner 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [(0, 'nsIndexType', ['sub'])] 2020-06-03T06:39:41Z DEBUG Updated 1 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG manager 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=manager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG manager 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG secretary 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=secretary,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG secretary 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG seeAlso 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=seeAlso,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG seeAlso 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [(0, 'nsIndexType', ['sub'])] 2020-06-03T06:39:41Z DEBUG Updated 1 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberOf 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=memberOf,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberOf 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG fqdn 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=fqdn,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG fqdn 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG macAddress 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=macAddress,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG macAddress 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG sourcehost 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=sourcehost,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG sourcehost 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberservice 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=memberservice,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberservice 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG managedby 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=managedby,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG managedby 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberallowcmd 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=memberallowcmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberallowcmd 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberdenycmd 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=memberdenycmd,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberdenycmd 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipasudorunas 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipasudorunas,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipasudorunas 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipasudorunasgroup 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipasudorunasgroup,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipasudorunasgroup 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG automountkey 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG add: 'pres' to nsIndexType, current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG add: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=automountkey,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG automountkey 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG automountMapName 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=automountMapName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG automountMapName 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaConfigString 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipaConfigString,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaConfigString 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaEnabledFlag 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipaEnabledFlag,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaEnabledFlag 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaKrbAuthzData 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipaKrbAuthzData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaKrbAuthzData 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipakrbprincipalalias 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipakrbprincipalalias,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipakrbprincipalalias 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipauniqueid 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipauniqueid,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipauniqueid 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG New entry: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipatokenradiusconfiglink 2020-06-03T06:39:41Z DEBUG ObjectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipatokenradiusconfiglink,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipatokenradiusconfiglink 2020-06-03T06:39:41Z DEBUG ObjectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG New entry: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaassignedidview 2020-06-03T06:39:41Z DEBUG ObjectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipaassignedidview,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaassignedidview 2020-06-03T06:39:41Z DEBUG ObjectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG New entry: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaallowedtarget 2020-06-03T06:39:41Z DEBUG ObjectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value [] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipaallowedtarget,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaallowedtarget 2020-06-03T06:39:41Z DEBUG ObjectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaMemberCa 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipaMemberCa,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaMemberCa 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaMemberCertProfile 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipaMemberCertProfile,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaMemberCertProfile 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG userCertificate 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsSystemIndex to 'false', current value ['false'] 2020-06-03T06:39:41Z DEBUG only: updated value ['false'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=userCertificate,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG userCertificate 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ntUniqueId 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ntUniqueId 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ntUserDomainId 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ntUserDomainId 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipalocation 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipalocation,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipalocation 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG krbPrincipalName 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsMatchingRule: 2020-06-03T06:39:41Z DEBUG caseIgnoreIA5Match 2020-06-03T06:39:41Z DEBUG caseExactIA5Match 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsMatchingRule to 'caseIgnoreIA5Match', current value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2020-06-03T06:39:41Z DEBUG only: updated value ['caseIgnoreIA5Match'] 2020-06-03T06:39:41Z DEBUG only: set nsMatchingRule to 'caseExactIA5Match', current value ['caseIgnoreIA5Match'] 2020-06-03T06:39:41Z DEBUG only: updated value ['caseIgnoreIA5Match', 'caseExactIA5Match'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=krbPrincipalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG krbPrincipalName 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsMatchingRule: 2020-06-03T06:39:41Z DEBUG caseIgnoreIA5Match 2020-06-03T06:39:41Z DEBUG caseExactIA5Match 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG krbCanonicalName 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsSystemIndex to 'false', current value ['false'] 2020-06-03T06:39:41Z DEBUG only: updated value ['false'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=krbCanonicalName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG krbCanonicalName 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG serverhostname 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG only: set nsSystemIndex to 'false', current value ['false'] 2020-06-03T06:39:41Z DEBUG only: updated value ['false'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'sub'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:41Z DEBUG only: set nsIndexType to 'sub', current value ['eq'] 2020-06-03T06:39:41Z DEBUG only: updated value ['eq', 'sub'] 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=serverhostname,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG serverhostname 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG description 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=description,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG description 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG l 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=l,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG l 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG nsOsVersion 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=nsOsVersion,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG nsOsVersion 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG nsHardwarePlatform 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=nsHardwarePlatform,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG nsHardwarePlatform 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG nsHostLocation 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=nsHostLocation,cn=index,cn=userroot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG nsHostLocation 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG sub 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsindex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipServicePort 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipServicePort,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipServicePort 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG accessRuleType 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=accessRuleType,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG accessRuleType 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG hostCategory 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=hostCategory,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG hostCategory 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG idnsName 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=idnsName,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG idnsName 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaCertmapData 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=ipaCertmapData,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG ipaCertmapData 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG altSecurityIdentities 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=altSecurityIdentities,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG altSecurityIdentities 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:41Z DEBUG Updating existing entry: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Initial value 2020-06-03T06:39:41Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberManager 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG --------------------------------------------- 2020-06-03T06:39:41Z DEBUG Final value after applying updates 2020-06-03T06:39:41Z DEBUG dn: cn=memberManager,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:41Z DEBUG cn: 2020-06-03T06:39:41Z DEBUG memberManager 2020-06-03T06:39:41Z DEBUG nsIndexType: 2020-06-03T06:39:41Z DEBUG eq 2020-06-03T06:39:41Z DEBUG pres 2020-06-03T06:39:41Z DEBUG nsSystemIndex: 2020-06-03T06:39:41Z DEBUG false 2020-06-03T06:39:41Z DEBUG objectClass: 2020-06-03T06:39:41Z DEBUG top 2020-06-03T06:39:41Z DEBUG nsIndex 2020-06-03T06:39:41Z DEBUG [] 2020-06-03T06:39:41Z DEBUG Updated 0 2020-06-03T06:39:41Z DEBUG Done 2020-06-03T06:39:46Z DEBUG Creating task cn=indextask_138104591868958060_8522,cn=index,cn=tasks,cn=config to index attributes: ipaallowedtarget, ipaassignedidview, ipatokenradiusconfiglink, member, memberuid, owner, seeAlso, uniquemember 2020-06-03T06:39:47Z DEBUG Indexing finished 2020-06-03T06:39:47Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-indices.update 6.230 sec 2020-06-03T06:39:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-ipaservers_hostgroup.update' 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG memberOf: 2020-06-03T06:39:47Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG member: 2020-06-03T06:39:47Z DEBUG fqdn=master1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG ipaUniqueID: 2020-06-03T06:39:47Z DEBUG 3c6879ce-a563-11ea-abc9-0242ac120002 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG ipaservers 2020-06-03T06:39:47Z DEBUG description: 2020-06-03T06:39:47Z DEBUG IPA server hosts 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG groupOfNames 2020-06-03T06:39:47Z DEBUG nestedGroup 2020-06-03T06:39:47Z DEBUG ipaobject 2020-06-03T06:39:47Z DEBUG ipahostgroup 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG memberOf: 2020-06-03T06:39:47Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG member: 2020-06-03T06:39:47Z DEBUG fqdn=master1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG ipaUniqueID: 2020-06-03T06:39:47Z DEBUG 3c6879ce-a563-11ea-abc9-0242ac120002 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG ipaservers 2020-06-03T06:39:47Z DEBUG description: 2020-06-03T06:39:47Z DEBUG IPA server hosts 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG groupOfNames 2020-06-03T06:39:47Z DEBUG nestedGroup 2020-06-03T06:39:47Z DEBUG ipaobject 2020-06-03T06:39:47Z DEBUG ipahostgroup 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG memberOf: 2020-06-03T06:39:47Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG member: 2020-06-03T06:39:47Z DEBUG fqdn=master1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG ipaUniqueID: 2020-06-03T06:39:47Z DEBUG 3c6879ce-a563-11ea-abc9-0242ac120002 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG ipaservers 2020-06-03T06:39:47Z DEBUG description: 2020-06-03T06:39:47Z DEBUG IPA server hosts 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG groupOfNames 2020-06-03T06:39:47Z DEBUG nestedGroup 2020-06-03T06:39:47Z DEBUG ipaobject 2020-06-03T06:39:47Z DEBUG ipahostgroup 2020-06-03T06:39:47Z DEBUG add: 'fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test' to member, current value ['fqdn=master1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test', 'fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG add: updated value ['fqdn=master1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test', 'fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG memberOf: 2020-06-03T06:39:47Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG member: 2020-06-03T06:39:47Z DEBUG fqdn=master1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG ipaUniqueID: 2020-06-03T06:39:47Z DEBUG 3c6879ce-a563-11ea-abc9-0242ac120002 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG ipaservers 2020-06-03T06:39:47Z DEBUG description: 2020-06-03T06:39:47Z DEBUG IPA server hosts 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG groupOfNames 2020-06-03T06:39:47Z DEBUG nestedGroup 2020-06-03T06:39:47Z DEBUG ipaobject 2020-06-03T06:39:47Z DEBUG ipahostgroup 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-ipaservers_hostgroup.update 0.008 sec 2020-06-03T06:39:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-nss_ldap.update' 2020-06-03T06:39:47Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG associatedDomain: 2020-06-03T06:39:47Z DEBUG ipa.test 2020-06-03T06:39:47Z DEBUG nisDomain: 2020-06-03T06:39:47Z DEBUG ipa.test 2020-06-03T06:39:47Z DEBUG info: 2020-06-03T06:39:47Z DEBUG IPA V2.0 2020-06-03T06:39:47Z DEBUG dc: 2020-06-03T06:39:47Z DEBUG ipa 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG domain 2020-06-03T06:39:47Z DEBUG pilotObject 2020-06-03T06:39:47Z DEBUG domainRelatedObject 2020-06-03T06:39:47Z DEBUG nisDomainObject 2020-06-03T06:39:47Z DEBUG aci: 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:47Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG add: 'domain' to objectClass, current value ['top', 'domain', 'pilotObject', 'domainRelatedObject', 'nisDomainObject'] 2020-06-03T06:39:47Z DEBUG add: updated value ['top', 'pilotObject', 'domainRelatedObject', 'nisDomainObject', 'domain'] 2020-06-03T06:39:47Z DEBUG add: 'domainRelatedObject' to objectClass, current value ['top', 'pilotObject', 'domainRelatedObject', 'nisDomainObject', 'domain'] 2020-06-03T06:39:47Z DEBUG add: updated value ['top', 'pilotObject', 'nisDomainObject', 'domain', 'domainRelatedObject'] 2020-06-03T06:39:47Z DEBUG add: 'nisDomainObject' to objectClass, current value ['top', 'pilotObject', 'nisDomainObject', 'domain', 'domainRelatedObject'] 2020-06-03T06:39:47Z DEBUG add: updated value ['top', 'pilotObject', 'domain', 'domainRelatedObject', 'nisDomainObject'] 2020-06-03T06:39:47Z DEBUG add: 'ipa.test' to associatedDomain, current value ['ipa.test'] 2020-06-03T06:39:47Z DEBUG add: updated value ['ipa.test'] 2020-06-03T06:39:47Z DEBUG add: 'ipa.test' to nisDomain, current value ['ipa.test'] 2020-06-03T06:39:47Z DEBUG add: updated value ['ipa.test'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG associatedDomain: 2020-06-03T06:39:47Z DEBUG ipa.test 2020-06-03T06:39:47Z DEBUG nisDomain: 2020-06-03T06:39:47Z DEBUG ipa.test 2020-06-03T06:39:47Z DEBUG info: 2020-06-03T06:39:47Z DEBUG IPA V2.0 2020-06-03T06:39:47Z DEBUG dc: 2020-06-03T06:39:47Z DEBUG ipa 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG pilotObject 2020-06-03T06:39:47Z DEBUG domain 2020-06-03T06:39:47Z DEBUG domainRelatedObject 2020-06-03T06:39:47Z DEBUG nisDomainObject 2020-06-03T06:39:47Z DEBUG aci: 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:47Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:47Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:47Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:47Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: ou=profile,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: ou=profile,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG ou: 2020-06-03T06:39:47Z DEBUG profiles 2020-06-03T06:39:47Z DEBUG profile 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG organizationalUnit 2020-06-03T06:39:47Z DEBUG aci: 2020-06-03T06:39:47Z DEBUG (targetattr = "attributemap || authenticationmethod || bindtimelimit || cn || createtimestamp || credentiallevel || defaultsearchbase || defaultsearchscope || defaultserverlist || dereferencealiases || entryusn || followreferrals || modifytimestamp || objectclass || objectclassmap || ou || preferredserverlist || profilettl || searchtimelimit || serviceauthenticationmethod || servicecredentiallevel || servicesearchdescriptor")(targetfilter = "(|(objectclass=organizationalUnit)(objectclass=DUAConfigProfile))")(version 3.0;acl "permission:System: Read DUA Profile";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG add: 'top' to objectClass, current value ['top', 'organizationalUnit'] 2020-06-03T06:39:47Z DEBUG add: updated value ['organizationalUnit', 'top'] 2020-06-03T06:39:47Z DEBUG add: 'organizationalUnit' to objectClass, current value ['organizationalUnit', 'top'] 2020-06-03T06:39:47Z DEBUG add: updated value ['top', 'organizationalUnit'] 2020-06-03T06:39:47Z DEBUG add: 'profiles' to ou, current value ['profiles', 'profile'] 2020-06-03T06:39:47Z DEBUG add: updated value ['profile', 'profiles'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: ou=profile,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG ou: 2020-06-03T06:39:47Z DEBUG profile 2020-06-03T06:39:47Z DEBUG profiles 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG organizationalUnit 2020-06-03T06:39:47Z DEBUG aci: 2020-06-03T06:39:47Z DEBUG (targetattr = "attributemap || authenticationmethod || bindtimelimit || cn || createtimestamp || credentiallevel || defaultsearchbase || defaultsearchscope || defaultserverlist || dereferencealiases || entryusn || followreferrals || modifytimestamp || objectclass || objectclassmap || ou || preferredserverlist || profilettl || searchtimelimit || serviceauthenticationmethod || servicecredentiallevel || servicesearchdescriptor")(targetfilter = "(|(objectclass=organizationalUnit)(objectclass=DUAConfigProfile))")(version 3.0;acl "permission:System: Read DUA Profile";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=default,ou=profile,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=default,ou=profile,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG followReferrals: 2020-06-03T06:39:47Z DEBUG TRUE 2020-06-03T06:39:47Z DEBUG objectclassMap: 2020-06-03T06:39:47Z DEBUG shadow:shadowAccount=posixAccount 2020-06-03T06:39:47Z DEBUG bindTimeLimit: 2020-06-03T06:39:47Z DEBUG 5 2020-06-03T06:39:47Z DEBUG serviceSearchDescriptor: 2020-06-03T06:39:47Z DEBUG passwd:cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG group:cn=groups,cn=compat,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG default 2020-06-03T06:39:47Z DEBUG searchTimeLimit: 2020-06-03T06:39:47Z DEBUG 15 2020-06-03T06:39:47Z DEBUG authenticationMethod: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG defaultSearchBase: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG defaultServerList: 2020-06-03T06:39:47Z DEBUG master1.ipa.test 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG DUAConfigProfile 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=default,ou=profile,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG followReferrals: 2020-06-03T06:39:47Z DEBUG TRUE 2020-06-03T06:39:47Z DEBUG objectclassMap: 2020-06-03T06:39:47Z DEBUG shadow:shadowAccount=posixAccount 2020-06-03T06:39:47Z DEBUG bindTimeLimit: 2020-06-03T06:39:47Z DEBUG 5 2020-06-03T06:39:47Z DEBUG serviceSearchDescriptor: 2020-06-03T06:39:47Z DEBUG passwd:cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG group:cn=groups,cn=compat,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG default 2020-06-03T06:39:47Z DEBUG searchTimeLimit: 2020-06-03T06:39:47Z DEBUG 15 2020-06-03T06:39:47Z DEBUG authenticationMethod: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG defaultSearchBase: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG defaultServerList: 2020-06-03T06:39:47Z DEBUG master1.ipa.test 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG DUAConfigProfile 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-nss_ldap.update 0.014 sec 2020-06-03T06:39:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-replication.update' 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=replication,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=replication,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG nsDS5ReplicaId: 2020-06-03T06:39:47Z DEBUG 7 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG replication 2020-06-03T06:39:47Z DEBUG nsDS5ReplicaRoot: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG nsDS5Replica 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG aci: 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicachangecount || nsds5replicacleanruv || nsds5replicaid || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicatombstonepurgeinterval || nsds5replicatype || nsds5task || nsstate || objectclass")(targetfilter = "(objectclass=nsds5replica)")(version 3.0;acl "permission:System: Read Replication Information";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=replication,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG nsDS5ReplicaId: 2020-06-03T06:39:47Z DEBUG 7 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG replication 2020-06-03T06:39:47Z DEBUG nsDS5ReplicaRoot: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG nsDS5Replica 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG aci: 2020-06-03T06:39:47Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsds5flags || nsds5replicaabortcleanruv || nsds5replicaautoreferral || nsds5replicabackoffmax || nsds5replicabackoffmin || nsds5replicabinddn || nsds5replicachangecount || nsds5replicacleanruv || nsds5replicaid || nsds5replicalegacyconsumer || nsds5replicaname || nsds5replicaprotocoltimeout || nsds5replicapurgedelay || nsds5replicareferral || nsds5replicaroot || nsds5replicatombstonepurgeinterval || nsds5replicatype || nsds5task || nsstate || objectclass")(targetfilter = "(objectclass=nsds5replica)")(version 3.0;acl "permission:System: Read Replication Information";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG member: 2020-06-03T06:39:47Z DEBUG krbprincipalname=ldap/master1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG krbprincipalname=ldap/replica1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG replication managers 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG groupofnames 2020-06-03T06:39:47Z DEBUG add: 'krbprincipalname=ldap/replica1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test' to member, current value ['krbprincipalname=ldap/master1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test', 'krbprincipalname=ldap/replica1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG add: updated value ['krbprincipalname=ldap/master1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test', 'krbprincipalname=ldap/replica1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG member: 2020-06-03T06:39:47Z DEBUG krbprincipalname=ldap/master1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG krbprincipalname=ldap/replica1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG replication managers 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG groupofnames 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG topology 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsContainer 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG topology 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsContainer 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=domain,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG domain 2020-06-03T06:39:47Z DEBUG nsds5ReplicaStripAttrs: 2020-06-03T06:39:47Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2020-06-03T06:39:47Z DEBUG nsDS5ReplicatedAttributeListTotal: 2020-06-03T06:39:47Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2020-06-03T06:39:47Z DEBUG nsDS5ReplicatedAttributeList: 2020-06-03T06:39:47Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2020-06-03T06:39:47Z DEBUG ipaReplTopoConfRoot: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG iparepltopoconf 2020-06-03T06:39:47Z DEBUG add: '(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeList, current value ['(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2020-06-03T06:39:47Z DEBUG add: updated value ['(objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2020-06-03T06:39:47Z DEBUG add: '(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount' to nsDS5ReplicatedAttributeListTotal, current value ['(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2020-06-03T06:39:47Z DEBUG add: updated value ['(objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount'] 2020-06-03T06:39:47Z DEBUG add: 'modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp' to nsds5ReplicaStripAttrs, current value ['modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2020-06-03T06:39:47Z DEBUG add: updated value ['modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=domain,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG domain 2020-06-03T06:39:47Z DEBUG nsds5ReplicaStripAttrs: 2020-06-03T06:39:47Z DEBUG modifiersName modifyTimestamp internalModifiersName internalModifyTimestamp 2020-06-03T06:39:47Z DEBUG nsDS5ReplicatedAttributeListTotal: 2020-06-03T06:39:47Z DEBUG (objectclass=*) $ EXCLUDE entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2020-06-03T06:39:47Z DEBUG nsDS5ReplicatedAttributeList: 2020-06-03T06:39:47Z DEBUG (objectclass=*) $ EXCLUDE memberof idnssoaserial entryusn krblastsuccessfulauth krblastfailedauth krbloginfailedcount 2020-06-03T06:39:47Z DEBUG ipaReplTopoConfRoot: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG iparepltopoconf 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Deleting entry cn=realm,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=realm,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test did not exist:no such entry 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsContainer 2020-06-03T06:39:47Z DEBUG ipaReplTopoManagedServer 2020-06-03T06:39:47Z DEBUG ipaConfigObject 2020-06-03T06:39:47Z DEBUG ipaSupportedDomainLevelConfig 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG replica1.ipa.test 2020-06-03T06:39:47Z DEBUG ipaReplTopoManagedSuffix: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG o=ipaca 2020-06-03T06:39:47Z DEBUG ipaMinDomainLevel: 2020-06-03T06:39:47Z DEBUG 1 2020-06-03T06:39:47Z DEBUG ipaMaxDomainLevel: 2020-06-03T06:39:47Z DEBUG 1 2020-06-03T06:39:47Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2020-06-03T06:39:47Z DEBUG add: updated value ['top', 'nsContainer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig', 'ipaReplTopoManagedServer'] 2020-06-03T06:39:47Z DEBUG add: 'dc=ipa,dc=test' to ipaReplTopoManagedSuffix, current value ['dc=ipa,dc=test', 'o=ipaca'] 2020-06-03T06:39:47Z DEBUG add: updated value ['o=ipaca', 'dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsContainer 2020-06-03T06:39:47Z DEBUG ipaConfigObject 2020-06-03T06:39:47Z DEBUG ipaSupportedDomainLevelConfig 2020-06-03T06:39:47Z DEBUG ipaReplTopoManagedServer 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG replica1.ipa.test 2020-06-03T06:39:47Z DEBUG ipaReplTopoManagedSuffix: 2020-06-03T06:39:47Z DEBUG o=ipaca 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG ipaMinDomainLevel: 2020-06-03T06:39:47Z DEBUG 1 2020-06-03T06:39:47Z DEBUG ipaMaxDomainLevel: 2020-06-03T06:39:47Z DEBUG 1 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=IPA Topology Configuration,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG IPA Topology Configuration 2020-06-03T06:39:47Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:47Z DEBUG ldbm database 2020-06-03T06:39:47Z DEBUG Multimaster Replication Plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:47Z DEBUG ipa-topology-plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:47Z DEBUG on 2020-06-03T06:39:47Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:47Z DEBUG ipa-topology-plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:47Z DEBUG ipa_topo_init 2020-06-03T06:39:47Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:47Z DEBUG libtopology 2020-06-03T06:39:47Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:47Z DEBUG object 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:47Z DEBUG freeipa 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:47Z DEBUG 1.0 2020-06-03T06:39:47Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2020-06-03T06:39:47Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG nsslapd-topo-plugin-shared-config-base: 2020-06-03T06:39:47Z DEBUG cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG o=ipaca 2020-06-03T06:39:47Z DEBUG nsslapd-topo-plugin-startup-delay: 2020-06-03T06:39:47Z DEBUG 20 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsSlapdPlugin 2020-06-03T06:39:47Z DEBUG extensibleObject 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=IPA Topology Configuration,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG IPA Topology Configuration 2020-06-03T06:39:47Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:47Z DEBUG ldbm database 2020-06-03T06:39:47Z DEBUG Multimaster Replication Plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:47Z DEBUG ipa-topology-plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:47Z DEBUG on 2020-06-03T06:39:47Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:47Z DEBUG ipa-topology-plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:47Z DEBUG ipa_topo_init 2020-06-03T06:39:47Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:47Z DEBUG libtopology 2020-06-03T06:39:47Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:47Z DEBUG object 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:47Z DEBUG freeipa 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:47Z DEBUG 1.0 2020-06-03T06:39:47Z DEBUG nsslapd-topo-plugin-shared-binddngroup: 2020-06-03T06:39:47Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG nsslapd-topo-plugin-shared-config-base: 2020-06-03T06:39:47Z DEBUG cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG nsslapd-topo-plugin-shared-replica-root: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG o=ipaca 2020-06-03T06:39:47Z DEBUG nsslapd-topo-plugin-startup-delay: 2020-06-03T06:39:47Z DEBUG 20 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsSlapdPlugin 2020-06-03T06:39:47Z DEBUG extensibleObject 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=changelog5,cn=config 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=changelog5,cn=config 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG changelog5 2020-06-03T06:39:47Z DEBUG nsslapd-changelogdir: 2020-06-03T06:39:47Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/cldb 2020-06-03T06:39:47Z DEBUG nsslapd-changelogmaxage: 2020-06-03T06:39:47Z DEBUG 7d 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG extensibleobject 2020-06-03T06:39:47Z DEBUG addifnew: '7d' to nsslapd-changelogmaxage, current value ['7d'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=changelog5,cn=config 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG changelog5 2020-06-03T06:39:47Z DEBUG nsslapd-changelogdir: 2020-06-03T06:39:47Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/cldb 2020-06-03T06:39:47Z DEBUG nsslapd-changelogmaxage: 2020-06-03T06:39:47Z DEBUG 7d 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG extensibleobject 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-replication.update 0.022 sec 2020-06-03T06:39:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-sslciphers.update' 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=encryption,cn=config 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=encryption,cn=config 2020-06-03T06:39:47Z DEBUG CACertExtractFile: 2020-06-03T06:39:47Z DEBUG /etc/dirsrv/slapd-IPA-TEST/Self-Signed-CA.pem 2020-06-03T06:39:47Z DEBUG allowWeakCipher: 2020-06-03T06:39:47Z DEBUG off 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG encryption 2020-06-03T06:39:47Z DEBUG nsSSL3Ciphers: 2020-06-03T06:39:47Z DEBUG default 2020-06-03T06:39:47Z DEBUG nsSSLClientAuth: 2020-06-03T06:39:47Z DEBUG allowed 2020-06-03T06:39:47Z DEBUG nsSSLSessionTimeout: 2020-06-03T06:39:47Z DEBUG 0 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsEncryptionConfig 2020-06-03T06:39:47Z DEBUG nsSSLSupportedCiphers: 2020-06-03T06:39:47Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2020-06-03T06:39:47Z DEBUG only: set nsSSL3Ciphers to 'default', current value ['default'] 2020-06-03T06:39:47Z DEBUG only: updated value ['default'] 2020-06-03T06:39:47Z DEBUG addifnew: 'off' to allowWeakCipher, current value ['off'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=encryption,cn=config 2020-06-03T06:39:47Z DEBUG CACertExtractFile: 2020-06-03T06:39:47Z DEBUG /etc/dirsrv/slapd-IPA-TEST/Self-Signed-CA.pem 2020-06-03T06:39:47Z DEBUG allowWeakCipher: 2020-06-03T06:39:47Z DEBUG off 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG encryption 2020-06-03T06:39:47Z DEBUG nsSSL3Ciphers: 2020-06-03T06:39:47Z DEBUG default 2020-06-03T06:39:47Z DEBUG nsSSLClientAuth: 2020-06-03T06:39:47Z DEBUG allowed 2020-06-03T06:39:47Z DEBUG nsSSLSessionTimeout: 2020-06-03T06:39:47Z DEBUG 0 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsEncryptionConfig 2020-06-03T06:39:47Z DEBUG nsSSLSupportedCiphers: 2020-06-03T06:39:47Z DEBUG TLS_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384::AES::SHA384::256 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256::CHACHA20POLY1305::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_128_GCM_SHA256::AES-GCM::AEAD::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_256_GCM_SHA384::AES-GCM::AEAD::256 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA::AES::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_128_CBC_SHA256::AES::SHA256::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_CAMELLIA_128_CBC_SHA::CAMELLIA::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA::AES::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_AES_256_CBC_SHA256::AES::SHA256::256 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_CAMELLIA_256_CBC_SHA::CAMELLIA::SHA1::256 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_SEED_CBC_SHA::SEED::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_3DES_EDE_CBC_SHA::3DES::SHA1::192 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_RC4_128_SHA::RC4::SHA1::128 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_RC4_128_MD5::RC4::MD5::128 2020-06-03T06:39:47Z DEBUG TLS_DHE_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-03T06:39:47Z DEBUG TLS_DHE_DSS_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_DES_CBC_SHA::DES::SHA1::64 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_ECDHE_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_ECDH_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_ECDH_ECDSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_NULL_SHA::NULL::SHA1::0 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_NULL_SHA256::NULL::SHA256::0 2020-06-03T06:39:47Z DEBUG TLS_RSA_WITH_NULL_MD5::NULL::MD5::0 2020-06-03T06:39:47Z DEBUG [] 2020-06-03T06:39:47Z DEBUG Updated 0 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-sslciphers.update 0.010 sec 2020-06-03T06:39:47Z DEBUG Parsing update file '/usr/share/ipa/updates/20-syncrepl.update' 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=Retro Changelog Plugin,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG Retro Changelog Plugin 2020-06-03T06:39:47Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:47Z DEBUG Class of Service 2020-06-03T06:39:47Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:47Z DEBUG database 2020-06-03T06:39:47Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:47Z DEBUG off 2020-06-03T06:39:47Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:47Z DEBUG retrocl_plugin_init 2020-06-03T06:39:47Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:47Z DEBUG libretrocl-plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:47Z DEBUG object 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:47Z DEBUG on 2020-06-03T06:39:47Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:47Z DEBUG 25 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsSlapdPlugin 2020-06-03T06:39:47Z DEBUG extensibleObject 2020-06-03T06:39:47Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value ['off'] 2020-06-03T06:39:47Z DEBUG only: updated value ['on'] 2020-06-03T06:39:47Z DEBUG add: 'nsuniqueid:targetUniqueId' to nsslapd-attribute, current value [] 2020-06-03T06:39:47Z DEBUG add: updated value ['nsuniqueid:targetUniqueId'] 2020-06-03T06:39:47Z DEBUG add: '2d' to nsslapd-changelogmaxage, current value [] 2020-06-03T06:39:47Z DEBUG add: updated value ['2d'] 2020-06-03T06:39:47Z DEBUG add: 'cn=dns,dc=ipa,dc=test' to nsslapd-include-suffix, current value [] 2020-06-03T06:39:47Z DEBUG add: updated value ['cn=dns,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=Retro Changelog Plugin,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG Retro Changelog Plugin 2020-06-03T06:39:47Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:47Z DEBUG Class of Service 2020-06-03T06:39:47Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:47Z DEBUG database 2020-06-03T06:39:47Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:47Z DEBUG on 2020-06-03T06:39:47Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:47Z DEBUG retrocl_plugin_init 2020-06-03T06:39:47Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:47Z DEBUG libretrocl-plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:47Z DEBUG object 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:47Z DEBUG none 2020-06-03T06:39:47Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:47Z DEBUG on 2020-06-03T06:39:47Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:47Z DEBUG 25 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsSlapdPlugin 2020-06-03T06:39:47Z DEBUG extensibleObject 2020-06-03T06:39:47Z DEBUG nsslapd-attribute: 2020-06-03T06:39:47Z DEBUG nsuniqueid:targetUniqueId 2020-06-03T06:39:47Z DEBUG nsslapd-changelogmaxage: 2020-06-03T06:39:47Z DEBUG 2d 2020-06-03T06:39:47Z DEBUG nsslapd-include-suffix: 2020-06-03T06:39:47Z DEBUG cn=dns,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG [(2, 'nsslapd-changelogmaxage', ['2d']), (2, 'nsslapd-include-suffix', ['cn=dns,dc=ipa,dc=test']), (2, 'nsslapd-attribute', ['nsuniqueid:targetUniqueId']), (2, 'nsslapd-pluginEnabled', ['on'])] 2020-06-03T06:39:47Z DEBUG Updated 1 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG MemberOf Plugin 2020-06-03T06:39:47Z DEBUG memberofattr: 2020-06-03T06:39:47Z DEBUG memberOf 2020-06-03T06:39:47Z DEBUG memberofgroupattr: 2020-06-03T06:39:47Z DEBUG member 2020-06-03T06:39:47Z DEBUG memberUser 2020-06-03T06:39:47Z DEBUG memberHost 2020-06-03T06:39:47Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:47Z DEBUG database 2020-06-03T06:39:47Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:47Z DEBUG memberof plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:47Z DEBUG on 2020-06-03T06:39:47Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:47Z DEBUG memberof 2020-06-03T06:39:47Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:47Z DEBUG memberof_postop_init 2020-06-03T06:39:47Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:47Z DEBUG libmemberof-plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:47Z DEBUG betxnpostoperation 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:47Z DEBUG 389 Project 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:47Z DEBUG 1.4.1.18 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsSlapdPlugin 2020-06-03T06:39:47Z DEBUG extensibleObject 2020-06-03T06:39:47Z DEBUG add: 'dc=ipa,dc=test' to memberofentryscope, current value [] 2020-06-03T06:39:47Z DEBUG add: updated value ['dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG add: 'cn=compat,dc=ipa,dc=test' to memberofentryscopeexcludesubtree, current value [] 2020-06-03T06:39:47Z DEBUG add: updated value ['cn=compat,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG add: 'cn=provisioning,dc=ipa,dc=test' to memberofentryscopeexcludesubtree, current value ['cn=compat,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG add: updated value ['cn=compat,dc=ipa,dc=test', 'cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test' to memberofentryscopeexcludesubtree, current value ['cn=compat,dc=ipa,dc=test', 'cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG add: updated value ['cn=compat,dc=ipa,dc=test', 'cn=provisioning,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Final value after applying updates 2020-06-03T06:39:47Z DEBUG dn: cn=MemberOf Plugin,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG MemberOf Plugin 2020-06-03T06:39:47Z DEBUG memberofattr: 2020-06-03T06:39:47Z DEBUG memberOf 2020-06-03T06:39:47Z DEBUG memberofgroupattr: 2020-06-03T06:39:47Z DEBUG member 2020-06-03T06:39:47Z DEBUG memberUser 2020-06-03T06:39:47Z DEBUG memberHost 2020-06-03T06:39:47Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:47Z DEBUG database 2020-06-03T06:39:47Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:47Z DEBUG memberof plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:47Z DEBUG on 2020-06-03T06:39:47Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:47Z DEBUG memberof 2020-06-03T06:39:47Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:47Z DEBUG memberof_postop_init 2020-06-03T06:39:47Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:47Z DEBUG libmemberof-plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:47Z DEBUG betxnpostoperation 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:47Z DEBUG 389 Project 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:47Z DEBUG 1.4.1.18 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsSlapdPlugin 2020-06-03T06:39:47Z DEBUG extensibleObject 2020-06-03T06:39:47Z DEBUG memberofentryscope: 2020-06-03T06:39:47Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG memberofentryscopeexcludesubtree: 2020-06-03T06:39:47Z DEBUG cn=compat,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:47Z DEBUG [(2, 'memberofentryscope', ['dc=ipa,dc=test']), (2, 'memberofentryscopeexcludesubtree', ['cn=compat,dc=ipa,dc=test', 'cn=provisioning,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test'])] 2020-06-03T06:39:47Z DEBUG Updated 1 2020-06-03T06:39:47Z DEBUG Done 2020-06-03T06:39:47Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG --------------------------------------------- 2020-06-03T06:39:47Z DEBUG Initial value 2020-06-03T06:39:47Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-03T06:39:47Z DEBUG cn: 2020-06-03T06:39:47Z DEBUG referential integrity postoperation 2020-06-03T06:39:47Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:47Z DEBUG database 2020-06-03T06:39:47Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:47Z DEBUG referential integrity plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:47Z DEBUG on 2020-06-03T06:39:47Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:47Z DEBUG referint 2020-06-03T06:39:47Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:47Z DEBUG referint_postop_init 2020-06-03T06:39:47Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:47Z DEBUG libreferint-plugin 2020-06-03T06:39:47Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:47Z DEBUG betxnpostoperation 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:47Z DEBUG 389 Project 2020-06-03T06:39:47Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:47Z DEBUG 1.4.1.18 2020-06-03T06:39:47Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:47Z DEBUG 40 2020-06-03T06:39:47Z DEBUG objectClass: 2020-06-03T06:39:47Z DEBUG top 2020-06-03T06:39:47Z DEBUG nsSlapdPlugin 2020-06-03T06:39:47Z DEBUG extensibleObject 2020-06-03T06:39:47Z DEBUG referint-logfile: 2020-06-03T06:39:47Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/referint 2020-06-03T06:39:47Z DEBUG referint-membership-attr: 2020-06-03T06:39:47Z DEBUG member 2020-06-03T06:39:47Z DEBUG uniquemember 2020-06-03T06:39:47Z DEBUG owner 2020-06-03T06:39:47Z DEBUG seeAlso 2020-06-03T06:39:47Z DEBUG referint-update-delay: 2020-06-03T06:39:47Z DEBUG 0 2020-06-03T06:39:48Z DEBUG add: 'dc=ipa,dc=test' to nsslapd-plugincontainerscope, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: 'dc=ipa,dc=test' to nsslapd-pluginentryscope, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: 'cn=provisioning,dc=ipa,dc=test' to nsslapd-pluginExcludeEntryScope, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG referential integrity postoperation 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG referential integrity plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG referint 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG referint_postop_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libreferint-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG betxnpostoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG 389 Project 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG referint-logfile: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/referint 2020-06-03T06:39:48Z DEBUG referint-membership-attr: 2020-06-03T06:39:48Z DEBUG member 2020-06-03T06:39:48Z DEBUG uniquemember 2020-06-03T06:39:48Z DEBUG owner 2020-06-03T06:39:48Z DEBUG seeAlso 2020-06-03T06:39:48Z DEBUG referint-update-delay: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-plugincontainerscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-pluginentryscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-pluginExcludeEntryScope: 2020-06-03T06:39:48Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG [(2, 'nsslapd-pluginExcludeEntryScope', ['cn=provisioning,dc=ipa,dc=test']), (2, 'nsslapd-plugincontainerscope', ['dc=ipa,dc=test']), (2, 'nsslapd-pluginentryscope', ['dc=ipa,dc=test'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Content Synchronization,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Content Synchronization 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:48Z DEBUG Retro Changelog Plugin 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG sync_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libcontentsync-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG object 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG only: set nsslapd-pluginEnabled to 'on', current value ['off'] 2020-06-03T06:39:48Z DEBUG only: updated value ['on'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Content Synchronization,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Content Synchronization 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-named: 2020-06-03T06:39:48Z DEBUG Retro Changelog Plugin 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG sync_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libcontentsync-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG object 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG [(2, 'nsslapd-pluginEnabled', ['on'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA Unique IDs 2020-06-03T06:39:48Z DEBUG ipauuidattr: 2020-06-03T06:39:48Z DEBUG ipaUniqueID 2020-06-03T06:39:48Z DEBUG ipauuidenforce: 2020-06-03T06:39:48Z DEBUG TRUE 2020-06-03T06:39:48Z DEBUG ipauuidfilter: 2020-06-03T06:39:48Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2020-06-03T06:39:48Z DEBUG ipauuidmagicregen: 2020-06-03T06:39:48Z DEBUG autogenerate 2020-06-03T06:39:48Z DEBUG ipauuidscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG add: 'cn=provisioning,dc=ipa,dc=test' to ipaUuidExcludeSubtree, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=provisioning,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=IPA Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA Unique IDs 2020-06-03T06:39:48Z DEBUG ipauuidattr: 2020-06-03T06:39:48Z DEBUG ipaUniqueID 2020-06-03T06:39:48Z DEBUG ipauuidenforce: 2020-06-03T06:39:48Z DEBUG TRUE 2020-06-03T06:39:48Z DEBUG ipauuidfilter: 2020-06-03T06:39:48Z DEBUG (|(objectclass=ipaObject)(objectclass=ipaAssociation)) 2020-06-03T06:39:48Z DEBUG ipauuidmagicregen: 2020-06-03T06:39:48Z DEBUG autogenerate 2020-06-03T06:39:48Z DEBUG ipauuidscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG ipaUuidExcludeSubtree: 2020-06-03T06:39:48Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG [(2, 'ipaUuidExcludeSubtree', ['cn=provisioning,dc=ipa,dc=test'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-syncrepl.update 0.080 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/20-user_private_groups.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG mepMappedAttr: 2020-06-03T06:39:48Z DEBUG cn: $uid 2020-06-03T06:39:48Z DEBUG gidNumber: $uidNumber 2020-06-03T06:39:48Z DEBUG description: User private group for $uid 2020-06-03T06:39:48Z DEBUG mepStaticAttr: 2020-06-03T06:39:48Z DEBUG objectclass: posixgroup 2020-06-03T06:39:48Z DEBUG objectclass: ipaobject 2020-06-03T06:39:48Z DEBUG ipaUniqueId: autogenerate 2020-06-03T06:39:48Z DEBUG mepRDNAttr: 2020-06-03T06:39:48Z DEBUG cn 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG UPG Template 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG mepTemplateEntry 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG mepMappedAttr: 2020-06-03T06:39:48Z DEBUG cn: $uid 2020-06-03T06:39:48Z DEBUG gidNumber: $uidNumber 2020-06-03T06:39:48Z DEBUG description: User private group for $uid 2020-06-03T06:39:48Z DEBUG mepStaticAttr: 2020-06-03T06:39:48Z DEBUG objectclass: posixgroup 2020-06-03T06:39:48Z DEBUG objectclass: ipaobject 2020-06-03T06:39:48Z DEBUG ipaUniqueId: autogenerate 2020-06-03T06:39:48Z DEBUG mepRDNAttr: 2020-06-03T06:39:48Z DEBUG cn 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG UPG Template 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG mepTemplateEntry 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG managedTemplate: 2020-06-03T06:39:48Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG managedBase: 2020-06-03T06:39:48Z DEBUG cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG originFilter: 2020-06-03T06:39:48Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2020-06-03T06:39:48Z DEBUG originScope: 2020-06-03T06:39:48Z DEBUG cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG UPG Definition 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG managedTemplate: 2020-06-03T06:39:48Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG managedBase: 2020-06-03T06:39:48Z DEBUG cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG originFilter: 2020-06-03T06:39:48Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2020-06-03T06:39:48Z DEBUG originScope: 2020-06-03T06:39:48Z DEBUG cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG UPG Definition 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG managedTemplate: 2020-06-03T06:39:48Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG managedBase: 2020-06-03T06:39:48Z DEBUG cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG originFilter: 2020-06-03T06:39:48Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2020-06-03T06:39:48Z DEBUG originScope: 2020-06-03T06:39:48Z DEBUG cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG UPG Definition 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG replace: objectclass=posixAccount not found, skipping 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG managedTemplate: 2020-06-03T06:39:48Z DEBUG cn=UPG Template,cn=Templates,cn=Managed Entries,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG managedBase: 2020-06-03T06:39:48Z DEBUG cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG originFilter: 2020-06-03T06:39:48Z DEBUG (&(objectclass=posixAccount)(!(description=__no_upg__))) 2020-06-03T06:39:48Z DEBUG originScope: 2020-06-03T06:39:48Z DEBUG cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG UPG Definition 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///cn=UPG Definition,cn=Definitions,cn=Managed Entries,cn=etc,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read UPG Definition";allow (compare,read,search) groupdn = "ldap:///cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-user_private_groups.update 0.008 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/20-uuid.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPK11 Unique IDs 2020-06-03T06:39:48Z DEBUG ipauuidattr: 2020-06-03T06:39:48Z DEBUG ipk11UniqueID 2020-06-03T06:39:48Z DEBUG ipauuidenforce: 2020-06-03T06:39:48Z DEBUG FALSE 2020-06-03T06:39:48Z DEBUG ipauuidfilter: 2020-06-03T06:39:48Z DEBUG (objectclass=ipk11Object) 2020-06-03T06:39:48Z DEBUG ipauuidmagicregen: 2020-06-03T06:39:48Z DEBUG autogenerate 2020-06-03T06:39:48Z DEBUG ipauuidscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPK11 Unique IDs 2020-06-03T06:39:48Z DEBUG ipauuidattr: 2020-06-03T06:39:48Z DEBUG ipk11UniqueID 2020-06-03T06:39:48Z DEBUG ipauuidenforce: 2020-06-03T06:39:48Z DEBUG FALSE 2020-06-03T06:39:48Z DEBUG ipauuidfilter: 2020-06-03T06:39:48Z DEBUG (objectclass=ipk11Object) 2020-06-03T06:39:48Z DEBUG ipauuidmagicregen: 2020-06-03T06:39:48Z DEBUG autogenerate 2020-06-03T06:39:48Z DEBUG ipauuidscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-uuid.update 0.003 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/20-whoami.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=whoami,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG whoami 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG whoami extended operation plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG whoami-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG whoami_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libwhoami-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG extendedop 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG 389 Project 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.4.1.18 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=whoami,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG whoami 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG whoami extended operation plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG whoami-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG whoami_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libwhoami-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG extendedop 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG 389 Project 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.4.1.18 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-whoami.update 0.004 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/20-winsync_index.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ntUniqueId 2020-06-03T06:39:48Z DEBUG nsIndexType: 2020-06-03T06:39:48Z DEBUG eq 2020-06-03T06:39:48Z DEBUG pres 2020-06-03T06:39:48Z DEBUG nsSystemIndex: 2020-06-03T06:39:48Z DEBUG false 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsIndex 2020-06-03T06:39:48Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-03T06:39:48Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:48Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:48Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ntUniqueId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ntUniqueId 2020-06-03T06:39:48Z DEBUG nsIndexType: 2020-06-03T06:39:48Z DEBUG eq 2020-06-03T06:39:48Z DEBUG pres 2020-06-03T06:39:48Z DEBUG nsSystemIndex: 2020-06-03T06:39:48Z DEBUG false 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsIndex 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ntUserDomainId 2020-06-03T06:39:48Z DEBUG nsIndexType: 2020-06-03T06:39:48Z DEBUG eq 2020-06-03T06:39:48Z DEBUG pres 2020-06-03T06:39:48Z DEBUG nsSystemIndex: 2020-06-03T06:39:48Z DEBUG false 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsIndex 2020-06-03T06:39:48Z DEBUG only: set nsIndexType to 'eq', current value ['eq', 'pres'] 2020-06-03T06:39:48Z DEBUG only: updated value ['eq'] 2020-06-03T06:39:48Z DEBUG only: set nsIndexType to 'pres', current value ['eq'] 2020-06-03T06:39:48Z DEBUG only: updated value ['eq', 'pres'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ntUserDomainId,cn=index,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ntUserDomainId 2020-06-03T06:39:48Z DEBUG nsIndexType: 2020-06-03T06:39:48Z DEBUG eq 2020-06-03T06:39:48Z DEBUG pres 2020-06-03T06:39:48Z DEBUG nsSystemIndex: 2020-06-03T06:39:48Z DEBUG false 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsIndex 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/20-winsync_index.update 0.004 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/21-ca_renewal_container.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ca_renewal 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Add CA Certificate For Renewal";allow (add) groupdn = "ldap:///cn=System: Add CA Certificate For Renewal,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Modify CA Certificate For Renewal";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate For Renewal,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Read CA Renewal Information";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2020-06-03T06:39:48Z DEBUG add: updated value ['nsContainer', 'top'] 2020-06-03T06:39:48Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2020-06-03T06:39:48Z DEBUG add: updated value ['top', 'nsContainer'] 2020-06-03T06:39:48Z DEBUG add: 'ca_renewal' to cn, current value ['ca_renewal'] 2020-06-03T06:39:48Z DEBUG add: updated value ['ca_renewal'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ca_renewal 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Add CA Certificate For Renewal";allow (add) groupdn = "ldap:///cn=System: Add CA Certificate For Renewal,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(target = "ldap:///cn=caSigningCert cert-pki-ca,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Modify CA Certificate For Renewal";allow (write) groupdn = "ldap:///cn=System: Modify CA Certificate For Renewal,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=pkiuser)")(version 3.0;acl "permission:System: Read CA Renewal Information";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-ca_renewal_container.update 0.002 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/21-certstore_container.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certificates 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2020-06-03T06:39:48Z DEBUG add: updated value ['nsContainer', 'top'] 2020-06-03T06:39:48Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2020-06-03T06:39:48Z DEBUG add: updated value ['top', 'nsContainer'] 2020-06-03T06:39:48Z DEBUG add: 'certificates' to cn, current value ['certificates'] 2020-06-03T06:39:48Z DEBUG add: updated value ['certificates'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certificates 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-certstore_container.update 0.002 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/21-replicas_container.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=replicas,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG replicas 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG add: 'top' to objectClass, current value ['nsContainer', 'top'] 2020-06-03T06:39:48Z DEBUG add: updated value ['nsContainer', 'top'] 2020-06-03T06:39:48Z DEBUG add: 'nsContainer' to objectClass, current value ['nsContainer', 'top'] 2020-06-03T06:39:48Z DEBUG add: updated value ['top', 'nsContainer'] 2020-06-03T06:39:48Z DEBUG add: 'replicas' to cn, current value ['replicas'] 2020-06-03T06:39:48Z DEBUG add: updated value ['replicas'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=replicas,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG replicas 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/21-replicas_container.update 0.002 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/25-referint.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG referential integrity postoperation 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG referential integrity plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG referint 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG referint_postop_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libreferint-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG betxnpostoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG 389 Project 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG referint-logfile: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/referint 2020-06-03T06:39:48Z DEBUG referint-membership-attr: 2020-06-03T06:39:48Z DEBUG member 2020-06-03T06:39:48Z DEBUG uniquemember 2020-06-03T06:39:48Z DEBUG owner 2020-06-03T06:39:48Z DEBUG seeAlso 2020-06-03T06:39:48Z DEBUG referint-update-delay: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-pluginexcludeentryscope: 2020-06-03T06:39:48Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-plugincontainerscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-pluginentryscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG add: 'manager' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager'] 2020-06-03T06:39:48Z DEBUG add: 'secretary' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary'] 2020-06-03T06:39:48Z DEBUG add: 'memberuser' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser'] 2020-06-03T06:39:48Z DEBUG add: 'memberhost' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost'] 2020-06-03T06:39:48Z DEBUG add: 'sourcehost' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost'] 2020-06-03T06:39:48Z DEBUG add: 'memberservice' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice'] 2020-06-03T06:39:48Z DEBUG add: 'managedby' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby'] 2020-06-03T06:39:48Z DEBUG add: 'memberallowcmd' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd'] 2020-06-03T06:39:48Z DEBUG add: 'memberdenycmd' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd'] 2020-06-03T06:39:48Z DEBUG add: 'ipasudorunas' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas'] 2020-06-03T06:39:48Z DEBUG add: 'ipasudorunasgroup' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup'] 2020-06-03T06:39:48Z DEBUG add: 'ipatokenradiusconfiglink' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink'] 2020-06-03T06:39:48Z DEBUG add: 'ipaassignedidview' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview'] 2020-06-03T06:39:48Z DEBUG add: 'ipaallowedtarget' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget'] 2020-06-03T06:39:48Z DEBUG add: 'ipamemberca' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca'] 2020-06-03T06:39:48Z DEBUG add: 'ipamembercertprofile' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile'] 2020-06-03T06:39:48Z DEBUG add: 'ipalocation' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation'] 2020-06-03T06:39:48Z DEBUG add: 'membermanager' to referint-membership-attr, current value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation'] 2020-06-03T06:39:48Z DEBUG add: updated value ['member', 'uniquemember', 'owner', 'seeAlso', 'manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=referential integrity postoperation,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG referential integrity postoperation 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG referential integrity plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG referint 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG referint_postop_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libreferint-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG betxnpostoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG 389 Project 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG referint-logfile: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/referint 2020-06-03T06:39:48Z DEBUG referint-membership-attr: 2020-06-03T06:39:48Z DEBUG member 2020-06-03T06:39:48Z DEBUG uniquemember 2020-06-03T06:39:48Z DEBUG owner 2020-06-03T06:39:48Z DEBUG seeAlso 2020-06-03T06:39:48Z DEBUG manager 2020-06-03T06:39:48Z DEBUG secretary 2020-06-03T06:39:48Z DEBUG memberuser 2020-06-03T06:39:48Z DEBUG memberhost 2020-06-03T06:39:48Z DEBUG sourcehost 2020-06-03T06:39:48Z DEBUG memberservice 2020-06-03T06:39:48Z DEBUG managedby 2020-06-03T06:39:48Z DEBUG memberallowcmd 2020-06-03T06:39:48Z DEBUG memberdenycmd 2020-06-03T06:39:48Z DEBUG ipasudorunas 2020-06-03T06:39:48Z DEBUG ipasudorunasgroup 2020-06-03T06:39:48Z DEBUG ipatokenradiusconfiglink 2020-06-03T06:39:48Z DEBUG ipaassignedidview 2020-06-03T06:39:48Z DEBUG ipaallowedtarget 2020-06-03T06:39:48Z DEBUG ipamemberca 2020-06-03T06:39:48Z DEBUG ipamembercertprofile 2020-06-03T06:39:48Z DEBUG ipalocation 2020-06-03T06:39:48Z DEBUG membermanager 2020-06-03T06:39:48Z DEBUG referint-update-delay: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-pluginexcludeentryscope: 2020-06-03T06:39:48Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-plugincontainerscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-pluginentryscope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG [(0, 'referint-membership-attr', ['manager', 'secretary', 'memberuser', 'memberhost', 'sourcehost', 'memberservice', 'managedby', 'memberallowcmd', 'memberdenycmd', 'ipasudorunas', 'ipasudorunasgroup', 'ipatokenradiusconfiglink', 'ipaassignedidview', 'ipaallowedtarget', 'ipamemberca', 'ipamembercertprofile', 'ipalocation', 'membermanager'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/25-referint.update 0.020 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/30-ipservices.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ipservices,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ipservices,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipservices 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ipservices,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipservices 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-ipservices.update 0.002 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/30-provisioning.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG provisioning 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG provisioning 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG accounts 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG accounts 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG staged users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG staged users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG deleted users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG deleted users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG staged users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG staged users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Add Stage User";allow (add) groupdn = "ldap:///cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Modify Stage User";allow (write) groupdn = "ldap:///cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage User password";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Read Stage Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=staged users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove Stage User";allow (delete) groupdn = "ldap:///cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="userPassword || krbPrincipalKey")(version 3.0; acl "Search existence of password and kerberos keys"; allow(read, search) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG deleted users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) userdn = "ldap:///uid=admin,cn=users,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG add: '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)' to aci, current value ['(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG deleted users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Preserved Users";allow (write) groupdn = "ldap:///cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read Preserved Users";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=*)")(version 3.0;acl "permission:System: Remove preserved User";allow (delete) groupdn = "ldap:///cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krblastpwdchange || krbpasswordexpiration || krbprincipalkey || userpassword")(target = "ldap:///uid=*,cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Reset Preserved User password";allow (read,search,write) groupdn = "ldap:///cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="userPassword || krbPrincipalKey || krbPasswordExpiration || krbLastPwdChange")(version 3.0; acl "Admins allowed to reset password and kerberos keys"; allow(read, search, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "No one can add entry in Delete container"; deny (add) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG provisioning accounts lock 2020-06-03T06:39:48Z DEBUG cosAttribute: 2020-06-03T06:39:48Z DEBUG nsaccountlock operational 2020-06-03T06:39:48Z DEBUG costemplatedn: 2020-06-03T06:39:48Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG cosSuperDefinition 2020-06-03T06:39:48Z DEBUG cosPointerDefinition 2020-06-03T06:39:48Z DEBUG ldapSubEntry 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=provisioning accounts lock,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG provisioning accounts lock 2020-06-03T06:39:48Z DEBUG cosAttribute: 2020-06-03T06:39:48Z DEBUG nsaccountlock operational 2020-06-03T06:39:48Z DEBUG costemplatedn: 2020-06-03T06:39:48Z DEBUG cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG cosSuperDefinition 2020-06-03T06:39:48Z DEBUG cosPointerDefinition 2020-06-03T06:39:48Z DEBUG ldapSubEntry 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Inactivation cos template 2020-06-03T06:39:48Z DEBUG cosPriority: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG cosTemplate 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Inactivation cos template,cn=accounts,cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Inactivation cos template 2020-06-03T06:39:48Z DEBUG cosPriority: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG cosTemplate 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-provisioning.update 0.017 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/30-s4u2proxy.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG s4u2proxy 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Add Service Delegations";allow (add) groupdn = "ldap:///cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaallowedtarget || memberprincipal")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Modify Service Delegation Membership";allow (write) groupdn = "ldap:///cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaallowedtarget || memberprincipal || modifytimestamp || objectclass")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Read Service Delegations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Remove Service Delegations";allow (delete) groupdn = "ldap:///cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG s4u2proxy 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Add Service Delegations";allow (add) groupdn = "ldap:///cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaallowedtarget || memberprincipal")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Modify Service Delegation Membership";allow (write) groupdn = "ldap:///cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaallowedtarget || memberprincipal || modifytimestamp || objectclass")(targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Read Service Delegations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=groupofprincipals)")(version 3.0;acl "permission:System: Remove Service Delegations";allow (delete) groupdn = "ldap:///cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaAllowedTarget: 2020-06-03T06:39:48Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberPrincipal: 2020-06-03T06:39:48Z DEBUG HTTP/master1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG HTTP/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa-http-delegation 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipaKrb5DelegationACL 2020-06-03T06:39:48Z DEBUG groupOfPrincipals 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaAllowedTarget: 2020-06-03T06:39:48Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberPrincipal: 2020-06-03T06:39:48Z DEBUG HTTP/master1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG HTTP/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa-http-delegation 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipaKrb5DelegationACL 2020-06-03T06:39:48Z DEBUG groupOfPrincipals 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberPrincipal: 2020-06-03T06:39:48Z DEBUG ldap/master1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG ldap/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa-ldap-delegation-targets 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupOfPrincipals 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberPrincipal: 2020-06-03T06:39:48Z DEBUG ldap/master1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG ldap/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa-ldap-delegation-targets 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupOfPrincipals 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaAllowedTarget: 2020-06-03T06:39:48Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberPrincipal: 2020-06-03T06:39:48Z DEBUG HTTP/master1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG HTTP/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa-http-delegation 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipaKrb5DelegationACL 2020-06-03T06:39:48Z DEBUG groupOfPrincipals 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG add: 'HTTP/replica1.ipa.test@IPA.TEST' to memberPrincipal, current value ['HTTP/master1.ipa.test@IPA.TEST', 'HTTP/replica1.ipa.test@IPA.TEST'] 2020-06-03T06:39:48Z DEBUG add: updated value ['HTTP/master1.ipa.test@IPA.TEST', 'HTTP/replica1.ipa.test@IPA.TEST'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaAllowedTarget: 2020-06-03T06:39:48Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberPrincipal: 2020-06-03T06:39:48Z DEBUG HTTP/master1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG HTTP/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa-http-delegation 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipaKrb5DelegationACL 2020-06-03T06:39:48Z DEBUG groupOfPrincipals 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberPrincipal: 2020-06-03T06:39:48Z DEBUG ldap/master1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG ldap/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa-ldap-delegation-targets 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupOfPrincipals 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG add: 'ldap/replica1.ipa.test@IPA.TEST' to memberPrincipal, current value ['ldap/master1.ipa.test@IPA.TEST', 'ldap/replica1.ipa.test@IPA.TEST'] 2020-06-03T06:39:48Z DEBUG add: updated value ['ldap/master1.ipa.test@IPA.TEST', 'ldap/replica1.ipa.test@IPA.TEST'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberPrincipal: 2020-06-03T06:39:48Z DEBUG ldap/master1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG ldap/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa-ldap-delegation-targets 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupOfPrincipals 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/30-s4u2proxy.update 0.010 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/37-locations.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=locations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=locations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG locations 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Add IPA Locations";allow (add) groupdn = "ldap:///cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "description")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Modify IPA Locations";allow (write) groupdn = "ldap:///cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || description || entryusn || idnsname || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Read IPA Locations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Remove IPA Locations";allow (delete) groupdn = "ldap:///cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=locations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG locations 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Add IPA Locations";allow (add) groupdn = "ldap:///cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "description")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Modify IPA Locations";allow (write) groupdn = "ldap:///cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || description || entryusn || idnsname || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Read IPA Locations";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipaLocationObject)")(version 3.0;acl "permission:System: Remove IPA Locations";allow (delete) groupdn = "ldap:///cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/37-locations.update 0.002 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-automember.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG automemberprocessmodifyops: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Auto Membership Plugin 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:48Z DEBUG cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG Auto Membership plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG Auto Membership 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG automember_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libautomember-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG betxnpreoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG 389 Project 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.4.1.18 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG addifnew: 'cn=automember,cn=etc,dc=ipa,dc=test' to nsslapd-pluginConfigArea, current value ['cn=automember,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Auto Membership Plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG automemberprocessmodifyops: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Auto Membership Plugin 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginConfigArea: 2020-06-03T06:39:48Z DEBUG cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG Auto Membership plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG Auto Membership 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG automember_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libautomember-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG betxnpreoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG 389 Project 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.4.1.18 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG automember 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "automemberdefaultgroup || automemberdisabled || automemberfilter || automembergroupingattr || automemberscope || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberdefinition)")(version 3.0;acl "permission:System: Read Automember Definitions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "automemberexclusiveregex || automemberinclusiveregex || automembertargetgroup || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberregexrule)")(version 3.0;acl "permission:System: Read Automember Rules";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG automember 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "automemberdefaultgroup || automemberdisabled || automemberfilter || automembergroupingattr || automemberscope || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberdefinition)")(version 3.0;acl "permission:System: Read Automember Definitions";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "automemberexclusiveregex || automemberinclusiveregex || automembertargetgroup || cn || createtimestamp || description || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=automemberregexrule)")(version 3.0;acl "permission:System: Read Automember Rules";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Hostgroup,cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG autoMemberGroupingAttr: 2020-06-03T06:39:48Z DEBUG member:dn 2020-06-03T06:39:48Z DEBUG autoMemberFilter: 2020-06-03T06:39:48Z DEBUG objectclass=ipaHost 2020-06-03T06:39:48Z DEBUG autoMemberScope: 2020-06-03T06:39:48Z DEBUG cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Hostgroup 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG autoMemberDefinition 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Hostgroup,cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG autoMemberGroupingAttr: 2020-06-03T06:39:48Z DEBUG member:dn 2020-06-03T06:39:48Z DEBUG autoMemberFilter: 2020-06-03T06:39:48Z DEBUG objectclass=ipaHost 2020-06-03T06:39:48Z DEBUG autoMemberScope: 2020-06-03T06:39:48Z DEBUG cn=computers,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Hostgroup 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG autoMemberDefinition 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Group,cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG autoMemberGroupingAttr: 2020-06-03T06:39:48Z DEBUG member:dn 2020-06-03T06:39:48Z DEBUG autoMemberFilter: 2020-06-03T06:39:48Z DEBUG objectclass=posixAccount 2020-06-03T06:39:48Z DEBUG autoMemberScope: 2020-06-03T06:39:48Z DEBUG cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Group 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG autoMemberDefinition 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Group,cn=automember,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG autoMemberGroupingAttr: 2020-06-03T06:39:48Z DEBUG member:dn 2020-06-03T06:39:48Z DEBUG autoMemberFilter: 2020-06-03T06:39:48Z DEBUG objectclass=posixAccount 2020-06-03T06:39:48Z DEBUG autoMemberScope: 2020-06-03T06:39:48Z DEBUG cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Group 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG autoMemberDefinition 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-automember.update 0.010 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-certprofile.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ca 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ca 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=certprofiles,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=certprofiles,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certprofiles 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Delete Certificate Profile";allow (delete) groupdn = "ldap:///cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Import Certificate Profile";allow (add) groupdn = "ldap:///cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipacertprofilestoreissued")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Modify Certificate Profile";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacertprofilestoreissued || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Read Certificate Profiles";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=certprofiles,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certprofiles 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Delete Certificate Profile";allow (delete) groupdn = "ldap:///cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Import Certificate Profile";allow (add) groupdn = "ldap:///cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipacertprofilestoreissued")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Modify Certificate Profile";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacertprofilestoreissued || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertprofile)")(version 3.0;acl "permission:System: Read Certificate Profiles";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-certprofile.update 0.003 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-delegation.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG nisDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG info: 2020-06-03T06:39:48Z DEBUG IPA V2.0 2020-06-03T06:39:48Z DEBUG dc: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG domain 2020-06-03T06:39:48Z DEBUG pilotObject 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nisDomainObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG add: '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG nisDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG info: 2020-06-03T06:39:48Z DEBUG IPA V2.0 2020-06-03T06:39:48Z DEBUG dc: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG domain 2020-06-03T06:39:48Z DEBUG pilotObject 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nisDomainObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG HBAC Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG HBAC Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG HBAC Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG HBAC Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Sudo Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Sudo Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Sudo Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Sudo Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Password Policy Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Password Policy Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Password Policy Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Password Policy Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Host Enrollment 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Host Enrollment 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test', 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test', 'cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Host Enrollment 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Host Enrollment 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG nisDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG info: 2020-06-03T06:39:48Z DEBUG IPA V2.0 2020-06-03T06:39:48Z DEBUG dc: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG domain 2020-06-03T06:39:48Z DEBUG pilotObject 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nisDomainObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries";allow (add) groupdn = "ldap:///cn=add dns entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries";allow (delete) groupdn = "ldap:///cn=remove dns entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries";allow (write) groupdn = "ldap:///cn=update dns entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG nisDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG info: 2020-06-03T06:39:48Z DEBUG IPA V2.0 2020-06-03T06:39:48Z DEBUG dc: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG domain 2020-06-03T06:39:48Z DEBUG pilotObject 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nisDomainObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG SELinux User Map Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG SELinux User Map Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=SELinux User Map Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove SELinux User Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG SELinux User Map Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG SELinux User Map Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Retrieve Certificates from the CA 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test' to member, current value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Retrieve Certificates from the CA 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Revoke Certificate 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG add: 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test' to member, current value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test', 'cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Revoke Certificate 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG add: '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(|(objectClass=ipaConfigObject)(dnahostname=*))")(version 3.0;acl "Admins can change GUI config"; allow (delete) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create own Custodia secrets"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage own Custodia secrets"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "IPA server hosts can create Dogtag Custodia secrets for same host"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*/($dn),cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey")(version 3.0; acl "IPA server hosts can manage Dogtag Custodia secrets for same host"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test" and userdn = "ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "ipaPublicKey || ipaKeyUsage || memberPrincipal")(version 3.0; acl "Dogtag service principals can search Custodia keys"; allow(read, search, compare) userdn = "ldap:///krbprincipalname=dogtag/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(version 3.0; acl "Add CA Certificates for renewals"; allow(add) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=*,cn=ca_renewal,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = "userCertificate")(version 3.0; acl "Modify CA Certificates for renewals"; allow(write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=CAcert,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr = cACertificate)(version 3.0; acl "Modify CA Certificate"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certificates 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG add: '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=certificates,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certificates 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Add Certificate Store Entry";allow (add) groupdn = "ldap:///cn=System: Add Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cacertificate || ipacertissuerserial || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Modify Certificate Store Entry";allow (write) groupdn = "ldap:///cn=System: Modify Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cacertificate || cn || createtimestamp || entryusn || ipacertissuerserial || ipacertsubject || ipaconfigstring || ipakeyextusage || ipakeytrust || ipakeyusage || ipapublickey || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Read Certificate Store Entries";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacertificate)")(version 3.0;acl "permission:System: Remove Certificate Store Entry";allow (delete) groupdn = "ldap:///cn=System: Remove Certificate Store Entry,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(&(objectClass=ipaCertificate)(ipaConfigString=ipaCA))")(targetattr = "ipaCertIssuerSerial || cACertificate")(version 3.0; acl "Modify CA Certificate Store Entry"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Automember Task Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Automember Task Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Tasks,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Automember Task Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Automember Task Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Add Automember Rebuild Membership Task 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Automember Task Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Add Automember Rebuild Membership Task 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG add: '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [(0, 'aci', ['(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG retrieve certificate 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG retrieve certificate 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG request certificate 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG request certificate 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG request certificate different host 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG request certificate different host 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certificate status 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certificate status 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG revoke certificate 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG revoke certificate 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certificate remove hold 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG certificate remove hold 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG request certificate ignore caacl 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG request certificate ignore caacl 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Request Certificate ignoring CA ACLs 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Certificate Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Request Certificate ignoring CA ACLs 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG nisDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG info: 2020-06-03T06:39:48Z DEBUG IPA V2.0 2020-06-03T06:39:48Z DEBUG dc: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG domain 2020-06-03T06:39:48Z DEBUG pilotObject 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nisDomainObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG add: '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG nisDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG info: 2020-06-03T06:39:48Z DEBUG IPA V2.0 2020-06-03T06:39:48Z DEBUG dc: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG domain 2020-06-03T06:39:48Z DEBUG pilotObject 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nisDomainObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=RBAC Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read roles, privileges, permissions and ACIs 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG RBAC Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=RBAC Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read roles, privileges, permissions and ACIs 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG RBAC Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read password policies 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Password Policy Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Password Policy Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read password policies 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Password Policy Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read global and per-user Kerberos ticket policy 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Kerberos Ticket Policy Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Kerberos Ticket Policy Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read global and per-user Kerberos ticket policy 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Kerberos Ticket Policy Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Automember Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read Automember definitions 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Automember Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Automember Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Definitions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Automember Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read Automember definitions 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Automember Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read list of IPA masters 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA Masters Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=IPA Masters Readers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Read list of IPA masters 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA Masters Readers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG masters 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' from aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) userdn = "ldap:///fqdn=replica1.ipa.test,cn=computers,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG masters 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=nsContainer)")(targetattr="objectclass || cn")(version 3.0; acl "Read access to masters"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(ipaConfigString=enabledService)")(targetattrs = "ipaConfigString")(version 3.0; acl "Find enabled services"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Allow hosts to read masters service configuration"; allow(read, search, compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipalocation || ipaserviceweight || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Locations of IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaConfigObject)")(version 3.0;acl "permission:System: Read Status of Services on IPA Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipaconfigstring || modifytimestamp || objectclass")(targetfilter = "(objectclass=nscontainer)")(version 3.0;acl "permission:System: Read IPA Masters";allow (compare,read,search) groupdn = "ldap:///cn=System: Read IPA Masters,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "cn || objectClass || ipaConfigString")(version 3.0; acl "Read IPA Masters"; allow (read, search, compare) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=nsContainer)")(targetattr = "ipaConfigString")(version 3.0; acl "Modify IPA Masters"; allow (write) groupdn = "ldap:///cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=PassSync Service,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG PassSync Service 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG PassSync Service 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=PassSync Service,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG PassSync Service 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG PassSync Service 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Read PassSync Managers Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Read PassSync Managers Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Modify PassSync Managers Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Modify PassSync Managers Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG add: '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [(0, 'aci', ['(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Read LDBM Database Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Read LDBM Database Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG add: '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [(0, 'aci', ['(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Add Configuration Sub-Entries 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Add Configuration Sub-Entries 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG add: '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";)', '(target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsslapdConfig 2020-06-03T06:39:48Z DEBUG nsslapd-backendconfig: 2020-06-03T06:39:48Z DEBUG cn=config,cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=config,cn=ipaca,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-betype: 2020-06-03T06:39:48Z DEBUG ldbm database 2020-06-03T06:39:48Z DEBUG nsslapd-privatenamespaces: 2020-06-03T06:39:48Z DEBUG cn=schema 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG cn=monitor 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-plugin: 2020-06-03T06:39:48Z DEBUG cn=binary syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bit string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=boolean syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case exact string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=case ignore string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=country string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=delivery method syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguished name syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=enhanced guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=facsimile telephone number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=fax syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalized time syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=guide syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integer syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=jpeg syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=name and optional uid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numeric string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octet string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=oid syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=postal address syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=printable string syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephone syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=teletex terminal identifier syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telex number syntax,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=octetstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=bitwise plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseexactia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=generalizedtimeorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=booleanmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5match,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreia5substringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoreorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignoresubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=caseignorelistsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifiermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=directorystringfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=objectidentifierfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=distinguishednamematch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=integerfirstcomponentmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=internationalization plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=uniquemembermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringorderingmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=numericstringsubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbermatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn=telephonenumbersubstringsmatch,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-requiresrestart: 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-port 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-secureport 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapifilepath 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-ldapilisten 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-workingdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-sslclientauth 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogdir 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogsuffix 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxentries 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-changelogmaxage 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-db-locks 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-maxdescriptors 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-return-exact-case 2020-06-03T06:39:48Z DEBUG cn=config:nsslapd-schema-ignore-trailing-spaces 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-idlistscanlimit 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-parentcheck 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbcachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-dbncache 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-cachesize 2020-06-03T06:39:48Z DEBUG cn=config,cn=ldbm:nsslapd-plugin 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslsessiontimeout 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nssslclientauth 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl2 2020-06-03T06:39:48Z DEBUG cn=encryption,cn=config:nsssl3 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-level: 2020-06-03T06:39:48Z DEBUG 16384 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logging-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-port: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-workingdir: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-maxthreadsperconn: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-localuser: 2020-06-03T06:39:48Z DEBUG dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordInHistory: 2020-06-03T06:39:48Z DEBUG 6 2020-06-03T06:39:48Z DEBUG passwordUnlock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordGraceLimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG passwordMustChange: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-local: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-pwpolicy-inherit-global: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-sizelimit: 2020-06-03T06:39:48Z DEBUG 2000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordWarning: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-mapping-fallback: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-threadnumber: 2020-06-03T06:39:48Z DEBUG 16 2020-06-03T06:39:48Z DEBUG passwordLockout: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enquote-sup-oc: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-localhost: 2020-06-03T06:39:48Z DEBUG replica1.ipa.test 2020-06-03T06:39:48Z DEBUG nsslapd-ioblocktimeout: 2020-06-03T06:39:48Z DEBUG 10000 2020-06-03T06:39:48Z DEBUG nsslapd-max-filter-nest-level: 2020-06-03T06:39:48Z DEBUG 40 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG passwordMinLength: 2020-06-03T06:39:48Z DEBUG 8 2020-06-03T06:39:48Z DEBUG passwordMinDigits: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinAlphas: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinUppers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinLowers: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinSpecials: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMin8bit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxRepeats: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMinCategories: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordMinTokenLength: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG passwordPalindrome: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictCheck: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordDictPath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordUserAttributes: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordBadWords: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordMaxSequence: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxSeqSets: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG passwordMaxClassChars: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/errors 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-schemacheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-schemamod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxcheck: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-syntaxlogging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-dn-validate-strict: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ds4-compatible-schema: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schema-ignore-trailing-spaces: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-schemareplace: 2020-06-03T06:39:48Z DEBUG replication-only 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG passwordMaxFailure: 2020-06-03T06:39:48Z DEBUG 3 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/access 2020-06-03T06:39:48Z DEBUG nsslapd-lastmod: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-security: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordMaxAge: 2020-06-03T06:39:48Z DEBUG 8640000 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG passwordResetFailureCount: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG passwordIsGlobalPolicy: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordLegacyPolicy: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordTrackUpdateTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-groupevalnestlevel: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-rootpw: 2020-06-03T06:39:48Z DEBUG {PBKDF2_SHA256}AAAIAJYSum4/+NpA3+Xjq5a7KFIFjNB5KNrgskP53OGa9CSPvBf86FKZQZHPr+YKKH2jRZeBifqXdO85IP6EJwzMocTeismLJTZjsATKkcM1krzsu3T+bmLJy2jRolem6hj0Qvrw7uTci5Cf7z6MjX1BxPnijcegyADpiCFDzwl+I2W4KvriNl/jEVpdPoGOQUCpktTkR75XvoobzRJKZc1mvvmZlcTp5fPIW5a2tHlSI4clOO0P72AiEP6cbwRbNRU1agLw5o5QVmm5AAd54/FG4SJRc18T+h0KkHizJ866TV7rayyOT2JyKzCv0leK51kPqzPsUCEW5rInxGU2YaRIPX+/QmAOrEfzFdFgVcm0ocnzuD9tlN9GtWx9aI/T57e5T/g5Om9v2fiJ8GrEJxnQnwfjLPs6umBGNsaDjYCyEDDY 2020-06-03T06:39:48Z DEBUG passwordChange: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-level: 2020-06-03T06:39:48Z DEBUG 256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-securePort: 2020-06-03T06:39:48Z DEBUG 636 2020-06-03T06:39:48Z DEBUG nsslapd-certmap-basedn: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-timelimit: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-reservedescriptors: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG nsslapd-svrtab: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG passwordExp: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG passwordSendExpiringTime: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-accesscontrol: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG day 2020-06-03T06:39:48Z DEBUG passwordLockoutDuration: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-idletimeout: 2020-06-03T06:39:48Z DEBUG 3600 2020-06-03T06:39:48Z DEBUG nsslapd-nagle: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logbuffering: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-csnlogging: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-allow-hashed-passwords: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG passwordCheckSyntax: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-snmp-index: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-ldapifilepath: 2020-06-03T06:39:48Z DEBUG /var/run/slapd-IPA-TEST.socket 2020-06-03T06:39:48Z DEBUG nsslapd-ldapilisten: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiautobind: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaprootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG nsslapd-ldapimaptoentries: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ldapiuidnumbertype: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapigidnumbertype: 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG nsslapd-ldapientrysearchbase: 2020-06-03T06:39:48Z DEBUG dc=example,dc=com 2020-06-03T06:39:48Z DEBUG nsslapd-anonlimitsdn: 2020-06-03T06:39:48Z DEBUG cn=anonymous-limits,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-counters: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-securelistenhost: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-rootdn: 2020-06-03T06:39:48Z DEBUG cn=Directory Manager 2020-06-03T06:39:48Z DEBUG passwordMinAge: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-return-exact-case: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-result-tweak: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-binddn-tracking: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-moddn-aci: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-attribute-name-exceptions: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-maxbersize: 2020-06-03T06:39:48Z DEBUG 209715200 2020-06-03T06:39:48Z DEBUG nsslapd-maxsasliosize: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-versionstring: 2020-06-03T06:39:48Z DEBUG 389-Directory/1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-referralmode: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-maxdescriptors: 2020-06-03T06:39:48Z DEBUG 1048576 2020-06-03T06:39:48Z DEBUG nsslapd-conntablesize: 2020-06-03T06:39:48Z DEBUG 1024 2020-06-03T06:39:48Z DEBUG nsslapd-SSLclientAuth: 2020-06-03T06:39:48Z DEBUG allowed 2020-06-03T06:39:48Z DEBUG nsslapd-config: 2020-06-03T06:39:48Z DEBUG cn=config 2020-06-03T06:39:48Z DEBUG nsslapd-instancedir: 2020-06-03T06:39:48Z DEBUG /usr/lib64/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-schemadir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST/schema 2020-06-03T06:39:48Z DEBUG nsslapd-lockdir: 2020-06-03T06:39:48Z DEBUG /var/lock/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-tmpdir: 2020-06-03T06:39:48Z DEBUG /tmp 2020-06-03T06:39:48Z DEBUG nsslapd-certdir: 2020-06-03T06:39:48Z DEBUG /etc/dirsrv/slapd-IPA-TEST 2020-06-03T06:39:48Z DEBUG nsslapd-ldifdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/ldif 2020-06-03T06:39:48Z DEBUG nsslapd-bakdir: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/bak 2020-06-03T06:39:48Z DEBUG nsslapd-saslpath: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rundir: 2020-06-03T06:39:48Z DEBUG /var/run/dirsrv 2020-06-03T06:39:48Z DEBUG nsslapd-rewrite-rfc1274: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-outbound-ldap-io-timeout: 2020-06-03T06:39:48Z DEBUG 300000 2020-06-03T06:39:48Z DEBUG nsslapd-allow-unauthenticated-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-secure-binds: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-allow-anonymous-access: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-localssf: 2020-06-03T06:39:48Z DEBUG 71 2020-06-03T06:39:48Z DEBUG nsslapd-minssf: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-minssf-exclude-rootdse: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-force-sasl-external: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-global: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-entryusn-import-initval: 2020-06-03T06:39:48Z DEBUG next 2020-06-03T06:39:48Z DEBUG nsslapd-validate-cert: 2020-06-03T06:39:48Z DEBUG warn 2020-06-03T06:39:48Z DEBUG nsslapd-pagedsizelimit: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-defaultnamingcontext: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-threshold: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-grace-period: 2020-06-03T06:39:48Z DEBUG 60 2020-06-03T06:39:48Z DEBUG nsslapd-disk-monitoring-logging-critical: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-ndn-cache-max-size: 2020-06-03T06:39:48Z DEBUG 20971520 2020-06-03T06:39:48Z DEBUG nsslapd-allowed-sasl-mechanisms: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-virtual-attrs: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-unhashed-pw-switch: 2020-06-03T06:39:48Z DEBUG nolog 2020-06-03T06:39:48Z DEBUG nsslapd-sasl-max-buffer-size: 2020-06-03T06:39:48Z DEBUG 2097152 2020-06-03T06:39:48Z DEBUG nsslapd-search-return-original-type-switch: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-enable-turbo-mode: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-connection-buffer: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-connection-nocanon: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-logging: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-listen-backlog-size: 2020-06-03T06:39:48Z DEBUG 128 2020-06-03T06:39:48Z DEBUG nsslapd-dynamic-plugins: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-cn-uses-dn-syntax-in-dns: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mxfast: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-trim-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-malloc-mmap-threshold: 2020-06-03T06:39:48Z DEBUG -10 2020-06-03T06:39:48Z DEBUG nsslapd-ignore-time-skew: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-global-backend-lock: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-maxsimplepaged-per-conn: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-enable-nunc-stans: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-mode: 2020-06-03T06:39:48Z DEBUG 600 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsync-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsynchour: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationsyncmin: 2020-06-03T06:39:48Z DEBUG 0 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logmaxdiskspace: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsize: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtime: 2020-06-03T06:39:48Z DEBUG 1 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-maxlogsperdir: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-enabled: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logging-hide-unhashed-pw: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logexpirationtimeunit: 2020-06-03T06:39:48Z DEBUG month 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logminfreediskspace: 2020-06-03T06:39:48Z DEBUG 5 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-logrotationtimeunit: 2020-06-03T06:39:48Z DEBUG week 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog: 2020-06-03T06:39:48Z DEBUG /var/log/dirsrv/slapd-IPA-TEST/audit 2020-06-03T06:39:48Z DEBUG nsslapd-logging-hr-timestamps-enabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-extract-pemfiles: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-logging-backend: 2020-06-03T06:39:48Z DEBUG dirsrv-log 2020-06-03T06:39:48Z DEBUG nsslapd-tls-check-crl: 2020-06-03T06:39:48Z DEBUG none 2020-06-03T06:39:48Z DEBUG nsslapd-enable-upgrade-hash: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-verify-filter-schema: 2020-06-03T06:39:48Z DEBUG process-safe 2020-06-03T06:39:48Z DEBUG passwordStorageScheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG passwordAdminDN: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-rootpwstoragescheme: 2020-06-03T06:39:48Z DEBUG PBKDF2_SHA256 2020-06-03T06:39:48Z DEBUG nsslapd-errorlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-accesslog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-auditlog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG nsslapd-ssl-check-hostname: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-hash-filters: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-auditfaillog-list: 2020-06-03T06:39:48Z DEBUG 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr != aci)(version 3.0; aci "cert manager read access"; allow (read, search, compare) userdn = "ldap:///uid=pkidbuser,ou=people,o=ipaca";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=automember rebuild membership,cn=tasks,cn=config")(targetattr=*)(version 3.0;acl "permission:Add Automember Rebuild Membership Task";allow (add) groupdn = "ldap:///cn=Add Automember Rebuild Membership Task,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || objectclass || passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Read PassSync Managers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "passsyncmanagersdns*")(target = "ldap:///cn=ipa_pwd_extop,cn=plugins,cn=config")(version 3.0;acl "permission:Modify PassSync Managers Configuration";allow (write) groupdn = "ldap:///cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || modifytimestamp || nsslapd-directory* || objectclass")(target = "ldap:///cn=config,cn=ldbm database,cn=plugins,cn=config")(version 3.0;acl "permission:Read LDBM Database Configuration";allow (compare,read,search) groupdn = "ldap:///cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [(0, 'aci', ['(version 3.0;acl "permission:Add Configuration Sub-Entries";allow (add) groupdn = "ldap:///cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=CA Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG CA Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG CA Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=CA Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Import Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Certificate Profile,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG CA Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG CA Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Vault Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Vault Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Vault Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Vault Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Vault Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Vault Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=DNS Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG DNS Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG DNS Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=DNS Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove IPA Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Locations of IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Status of Services on IPA Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG DNS Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG DNS Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=DNS Servers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG krbprincipalname=DNS/master1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG krbprincipalname=ipa-dnskeysyncd/master1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG DNS Servers 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG DNS Servers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=DNS Servers,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG krbprincipalname=DNS/master1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG krbprincipalname=ipa-dnskeysyncd/master1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG DNS Servers 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG DNS Servers 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-delegation.update 0.505 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-dns.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=dns,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=dns,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG idnsAllowSyncPTR: 2020-06-03T06:39:48Z DEBUG TRUE 2020-06-03T06:39:48Z DEBUG ipaDNSVersion: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG ipaConfigString: 2020-06-03T06:39:48Z DEBUG DNSVersion 1 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG dns 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG idnsConfigObject 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG ipaConfigObject 2020-06-03T06:39:48Z DEBUG ipaDNSContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG addifexist: 'idnsConfigObject' to objectClass, current value ['idnsConfigObject', 'nsContainer', 'ipaConfigObject', 'ipaDNSContainer', 'top'] 2020-06-03T06:39:48Z DEBUG addifexist: set objectClass to ['idnsConfigObject', 'nsContainer', 'ipaConfigObject', 'ipaDNSContainer', 'top', 'idnsConfigObject'] 2020-06-03T06:39:48Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value ['(targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG addifexist: set aci to ['(targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG addifexist: '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)' to aci, current value ['(targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG addifexist: set aci to ['(targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' to aci, current value ['(targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG addifexist: set aci to ['(targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG addifexist: set aci to ['(targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=dns,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG idnsAllowSyncPTR: 2020-06-03T06:39:48Z DEBUG TRUE 2020-06-03T06:39:48Z DEBUG ipaDNSVersion: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG ipaConfigString: 2020-06-03T06:39:48Z DEBUG DNSVersion 1 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG dns 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG idnsConfigObject 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG ipaConfigObject 2020-06-03T06:39:48Z DEBUG ipaDNSContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG idnsConfigObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=dns,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=dns,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG idnsAllowSyncPTR: 2020-06-03T06:39:48Z DEBUG TRUE 2020-06-03T06:39:48Z DEBUG ipaDNSVersion: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG ipaConfigString: 2020-06-03T06:39:48Z DEBUG DNSVersion 1 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG dns 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG idnsConfigObject 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG ipaConfigObject 2020-06-03T06:39:48Z DEBUG ipaDNSContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG replace: (targetattr = "*")(version 3.0; acl "No access to DNS tree without a permission"; deny (read,search,compare) (groupdn != "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test") and (groupdn != "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test");) not found, skipping 2020-06-03T06:39:48Z DEBUG replace: updated value ['(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=dns,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG idnsAllowSyncPTR: 2020-06-03T06:39:48Z DEBUG TRUE 2020-06-03T06:39:48Z DEBUG ipaDNSVersion: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG ipaConfigString: 2020-06-03T06:39:48Z DEBUG DNSVersion 1 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG dns 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG idnsConfigObject 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG ipaConfigObject 2020-06-03T06:39:48Z DEBUG ipaDNSContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG [(1, 'aci', ['(targetattr = "*")(version 3.0; acl "Allow read access"; allow (read,search,compare) groupdn = "ldap:///cn=Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test" or userattr = "parent[0,1].managedby#GROUPDN";)']), (0, 'aci', ['(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=dns,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=dns,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG idnsAllowSyncPTR: 2020-06-03T06:39:48Z DEBUG TRUE 2020-06-03T06:39:48Z DEBUG ipaDNSVersion: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG ipaConfigString: 2020-06-03T06:39:48Z DEBUG DNSVersion 1 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG dns 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG idnsConfigObject 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG ipaConfigObject 2020-06-03T06:39:48Z DEBUG ipaDNSContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value ['(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value ['(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value ['(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "idnsname || cn || idnsallowdynupdate || dnsttl || dnsclass || arecord || aaaarecord || a6record || nsrecord || cnamerecord || ptrrecord || srvrecord || txtrecord || mxrecord || mdrecord || hinforecord || minforecord || afsdbrecord || sigrecord || keyrecord || locrecord || nxtrecord || naptrrecord || kxrecord || certrecord || dnamerecord || dsrecord || sshfprecord || rrsigrecord || nsecrecord || idnsname || idnszoneactive || idnssoamname || idnssoarname || idnssoaserial || idnssoarefresh || idnssoaretry || idnssoaexpire || idnssoaminimum || idnsupdatepolicy || idnsallowquery || idnsallowtransfer || idnsallowsyncptr || idnsforwardpolicy || idnsforwarders || dlvrecord || idnssecinlinesigning || nsec3paramrecord || tlsarecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' from aci, current value ['(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)', '(targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";)' not in aci 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=dns,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG idnsAllowSyncPTR: 2020-06-03T06:39:48Z DEBUG TRUE 2020-06-03T06:39:48Z DEBUG ipaDNSVersion: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG ipaConfigString: 2020-06-03T06:39:48Z DEBUG DNSVersion 1 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG dns 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG idnsConfigObject 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG ipaConfigObject 2020-06-03T06:39:48Z DEBUG ipaDNSContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Add DNS entries in a zone";allow (add) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Remove DNS entries from a zone";allow (delete) userattr = "parent[1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || mdrecord || minforecord || mxrecord || naptrrecord || nsecrecord || nsec3paramrecord || nsrecord || nxtrecord || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || urirecord || unknownrecord ")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "Update DNS entries in a zone";allow (write) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aaaarecord || arecord || cnamerecord || idnsname || objectclass || ptrrecord")(targetfilter = "(&(objectclass=idnsrecord)(|(aaaarecord=*)(arecord=*)(cnamerecord=*)(ptrrecord=*)(idnsZoneActive=TRUE)))")(version 3.0; acl "Allow hosts to read DNS A/AAA/CNAME/PTR records"; allow (read,search,compare) userdn = "ldap:///fqdn=*,cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "*")(version 3.0; acl "Read DNS entries from a zone"; allow (read,search,compare) userattr = "parent[0,1].managedby#GROUPDN";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=IPA DNS,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA DNS 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG IPA DNS support plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG ipa_dns 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG ipadns_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libipa_dns.so 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG preoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG Red Hat, Inc. 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.0 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsslapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=IPA DNS,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA DNS 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG IPA DNS support plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG ipa_dns 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG ipadns_init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libipa_dns.so 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG preoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG Red Hat, Inc. 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.0 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsslapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-dns.update 0.019 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-otp.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=otp,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=otp,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG otp 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=otp,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG otp 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=otp,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=otp,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipatokenHOTPsyncWindow: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG ipatokenHOTPauthWindow: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG ipatokenTOTPsyncWindow: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG ipatokenTOTPauthWindow: 2020-06-03T06:39:48Z DEBUG 300 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG otp 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipatokenOTPConfig 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || ipatokenhotpauthwindow || ipatokenhotpsyncwindow || ipatokentotpauthwindow || ipatokentotpsyncwindow")(targetfilter = "(objectclass=ipatokenotpconfig)")(version 3.0;acl "permission:System: Read OTP Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=otp,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipatokenHOTPsyncWindow: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG ipatokenHOTPauthWindow: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG ipatokenTOTPsyncWindow: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG ipatokenTOTPauthWindow: 2020-06-03T06:39:48Z DEBUG 300 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG otp 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipatokenOTPConfig 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || ipatokenhotpauthwindow || ipatokenhotpsyncwindow || ipatokentotpauthwindow || ipatokentotpsyncwindow")(targetfilter = "(objectclass=ipatokenotpconfig)")(version 3.0;acl "permission:System: Read OTP Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG nisDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG info: 2020-06-03T06:39:48Z DEBUG IPA V2.0 2020-06-03T06:39:48Z DEBUG dc: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG domain 2020-06-03T06:39:48Z DEBUG pilotObject 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nisDomainObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG remove: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create and delete tokens"; allow (add, delete) userattr = "ipatokenOwner#SELFDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "ipatokenUniqueID || description || ipatokenOwner || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Users can write basic token info"; allow (write) userattr = "ipatokenOwner#USERDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPclockOffset || ipatokenTOTPtimeStep")(version 3.0; acl "Users can add TOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPkey || ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenHOTPcounter")(version 3.0; acl "Users can add HOTP token secrets"; allow (write, search) userattr = "ipatokenOwner#USERDN";)' not in aci 2020-06-03T06:39:48Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG nisDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG info: 2020-06-03T06:39:48Z DEBUG IPA V2.0 2020-06-03T06:39:48Z DEBUG dc: 2020-06-03T06:39:48Z DEBUG ipa 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG domain 2020-06-03T06:39:48Z DEBUG pilotObject 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nisDomainObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:48Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=radiusproxy,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=radiusproxy,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG radiusproxy 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipatokenradiusretries || ipatokenradiusserver || ipatokenradiustimeout || ipatokenusermapattribute || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipatokenradiusconfiguration)")(version 3.0;acl "permission:System: Read Radius Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=radiusproxy,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG radiusproxy 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipatokenradiusretries || ipatokenradiusserver || ipatokenradiustimeout || ipatokenusermapattribute || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipatokenradiusconfiguration)")(version 3.0;acl "permission:System: Read Radius Servers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG New entry: cn=IPA OTP Last Token,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG objectclass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA OTP Last Token 2020-06-03T06:39:48Z DEBUG nsslapd-pluginpath: 2020-06-03T06:39:48Z DEBUG libipa_otp_lasttoken 2020-06-03T06:39:48Z DEBUG nsslapd-plugininitfunc: 2020-06-03T06:39:48Z DEBUG ipa_otp_lasttoken_init 2020-06-03T06:39:48Z DEBUG nsslapd-plugintype: 2020-06-03T06:39:48Z DEBUG preoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginenabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginid: 2020-06-03T06:39:48Z DEBUG ipa-otp-lasttoken 2020-06-03T06:39:48Z DEBUG nsslapd-pluginversion: 2020-06-03T06:39:48Z DEBUG 1.0 2020-06-03T06:39:48Z DEBUG nsslapd-pluginvendor: 2020-06-03T06:39:48Z DEBUG Red Hat, Inc. 2020-06-03T06:39:48Z DEBUG nsslapd-plugindescription: 2020-06-03T06:39:48Z DEBUG IPA OTP Last Token plugin 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=IPA OTP Last Token,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG objectclass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA OTP Last Token 2020-06-03T06:39:48Z DEBUG nsslapd-pluginpath: 2020-06-03T06:39:48Z DEBUG libipa_otp_lasttoken 2020-06-03T06:39:48Z DEBUG nsslapd-plugininitfunc: 2020-06-03T06:39:48Z DEBUG ipa_otp_lasttoken_init 2020-06-03T06:39:48Z DEBUG nsslapd-plugintype: 2020-06-03T06:39:48Z DEBUG preoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginenabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginid: 2020-06-03T06:39:48Z DEBUG ipa-otp-lasttoken 2020-06-03T06:39:48Z DEBUG nsslapd-pluginversion: 2020-06-03T06:39:48Z DEBUG 1.0 2020-06-03T06:39:48Z DEBUG nsslapd-pluginvendor: 2020-06-03T06:39:48Z DEBUG Red Hat, Inc. 2020-06-03T06:39:48Z DEBUG nsslapd-plugindescription: 2020-06-03T06:39:48Z DEBUG IPA OTP Last Token plugin 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG New entry: cn=IPA OTP Counter,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG objectclass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA OTP Counter 2020-06-03T06:39:48Z DEBUG nsslapd-pluginpath: 2020-06-03T06:39:48Z DEBUG libipa_otp_counter 2020-06-03T06:39:48Z DEBUG nsslapd-plugininitfunc: 2020-06-03T06:39:48Z DEBUG ipa_otp_counter_init 2020-06-03T06:39:48Z DEBUG nsslapd-plugintype: 2020-06-03T06:39:48Z DEBUG preoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginenabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginid: 2020-06-03T06:39:48Z DEBUG ipa-otp-counter 2020-06-03T06:39:48Z DEBUG nsslapd-pluginversion: 2020-06-03T06:39:48Z DEBUG 1.0 2020-06-03T06:39:48Z DEBUG nsslapd-pluginvendor: 2020-06-03T06:39:48Z DEBUG Red Hat, Inc. 2020-06-03T06:39:48Z DEBUG nsslapd-plugindescription: 2020-06-03T06:39:48Z DEBUG IPA OTP Counter plugin 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=IPA OTP Counter,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG objectclass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA OTP Counter 2020-06-03T06:39:48Z DEBUG nsslapd-pluginpath: 2020-06-03T06:39:48Z DEBUG libipa_otp_counter 2020-06-03T06:39:48Z DEBUG nsslapd-plugininitfunc: 2020-06-03T06:39:48Z DEBUG ipa_otp_counter_init 2020-06-03T06:39:48Z DEBUG nsslapd-plugintype: 2020-06-03T06:39:48Z DEBUG preoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginenabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginid: 2020-06-03T06:39:48Z DEBUG ipa-otp-counter 2020-06-03T06:39:48Z DEBUG nsslapd-pluginversion: 2020-06-03T06:39:48Z DEBUG 1.0 2020-06-03T06:39:48Z DEBUG nsslapd-pluginvendor: 2020-06-03T06:39:48Z DEBUG Red Hat, Inc. 2020-06-03T06:39:48Z DEBUG nsslapd-plugindescription: 2020-06-03T06:39:48Z DEBUG IPA OTP Counter plugin 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-otp.update 0.047 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-realm_domains.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Realm Domains,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Realm Domains 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "associateddomain")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Modify Realm Domains";allow (write) groupdn = "ldap:///cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "associateddomain || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Read Realm Domains";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Realm Domains,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG associatedDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Realm Domains 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG domainRelatedObject 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "associateddomain")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Modify Realm Domains";allow (write) groupdn = "ldap:///cn=System: Modify Realm Domains,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "associateddomain || cn || createtimestamp || entryusn || modifytimestamp || objectclass")(targetfilter = "(objectclass=domainrelatedobject)")(version 3.0;acl "permission:System: Read Realm Domains";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-realm_domains.update 0.003 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-replication.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG userRoot 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsBackendInstance 2020-06-03T06:39:48Z DEBUG nsslapd-suffix: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-cachesize: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-cachememsize: 2020-06-03T06:39:48Z DEBUG 134217728 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-index: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-directory: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/db/userRoot 2020-06-03T06:39:48Z DEBUG nsslapd-dncachememsize: 2020-06-03T06:39:48Z DEBUG 67108864 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG add: '(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG userRoot 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG nsBackendInstance 2020-06-03T06:39:48Z DEBUG nsslapd-suffix: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG nsslapd-cachesize: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG nsslapd-cachememsize: 2020-06-03T06:39:48Z DEBUG 134217728 2020-06-03T06:39:48Z DEBUG nsslapd-readonly: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-require-index: 2020-06-03T06:39:48Z DEBUG off 2020-06-03T06:39:48Z DEBUG nsslapd-directory: 2020-06-03T06:39:48Z DEBUG /var/lib/dirsrv/slapd-IPA-TEST/db/userRoot 2020-06-03T06:39:48Z DEBUG nsslapd-dncachememsize: 2020-06-03T06:39:48Z DEBUG 67108864 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr=nsslapd-readonly)(version 3.0; acl "Allow marking the database readonly"; allow (write) groupdn = "ldap:///cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Modify DNA Range 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Modify DNA Range 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Posix IDs 2020-06-03T06:39:48Z DEBUG dnaExcludeScope: 2020-06-03T06:39:48Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaFilter: 2020-06-03T06:39:48Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-03T06:39:48Z DEBUG dnaMagicRegen: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG dnaMaxValue: 2020-06-03T06:39:48Z DEBUG 1100 2020-06-03T06:39:48Z DEBUG dnaNextValue: 2020-06-03T06:39:48Z DEBUG 1101 2020-06-03T06:39:48Z DEBUG dnaScope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaSharedCfgDN: 2020-06-03T06:39:48Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaThreshold: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG dnaType: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG add: '(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Posix IDs 2020-06-03T06:39:48Z DEBUG dnaExcludeScope: 2020-06-03T06:39:48Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaFilter: 2020-06-03T06:39:48Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-03T06:39:48Z DEBUG dnaMagicRegen: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG dnaMaxValue: 2020-06-03T06:39:48Z DEBUG 1100 2020-06-03T06:39:48Z DEBUG dnaNextValue: 2020-06-03T06:39:48Z DEBUG 1101 2020-06-03T06:39:48Z DEBUG dnaScope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaSharedCfgDN: 2020-06-03T06:39:48Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaThreshold: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG dnaType: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Read DNA Range 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaPermissionType: 2020-06-03T06:39:48Z DEBUG SYSTEM 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Read DNA Range 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipapermission 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Posix IDs 2020-06-03T06:39:48Z DEBUG dnaExcludeScope: 2020-06-03T06:39:48Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaFilter: 2020-06-03T06:39:48Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-03T06:39:48Z DEBUG dnaMagicRegen: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG dnaMaxValue: 2020-06-03T06:39:48Z DEBUG 1100 2020-06-03T06:39:48Z DEBUG dnaNextValue: 2020-06-03T06:39:48Z DEBUG 1101 2020-06-03T06:39:48Z DEBUG dnaScope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaSharedCfgDN: 2020-06-03T06:39:48Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaThreshold: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG dnaType: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG add: '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to aci, current value ['(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG add: updated value ['(targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Posix IDs 2020-06-03T06:39:48Z DEBUG dnaExcludeScope: 2020-06-03T06:39:48Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaFilter: 2020-06-03T06:39:48Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-03T06:39:48Z DEBUG dnaMagicRegen: 2020-06-03T06:39:48Z DEBUG -1 2020-06-03T06:39:48Z DEBUG dnaMaxValue: 2020-06-03T06:39:48Z DEBUG 1100 2020-06-03T06:39:48Z DEBUG dnaNextValue: 2020-06-03T06:39:48Z DEBUG 1101 2020-06-03T06:39:48Z DEBUG dnaScope: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaSharedCfgDN: 2020-06-03T06:39:48Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG dnaThreshold: 2020-06-03T06:39:48Z DEBUG 500 2020-06-03T06:39:48Z DEBUG dnaType: 2020-06-03T06:39:48Z DEBUG uidNumber 2020-06-03T06:39:48Z DEBUG gidNumber 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [(0, 'aci', ['(targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";)'])] 2020-06-03T06:39:48Z DEBUG Updated 1 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-replication.update 0.030 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/40-vault.update' 2020-06-03T06:39:48Z DEBUG New entry: cn=vaults,cn=kra,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=vaults,cn=kra,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=ipa,dc=test")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=ipa,dc=test";)' from aci, current value [] 2020-06-03T06:39:48Z DEBUG remove: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=ipa,dc=test")(version 3.0; acl "Allow users to create private container"; allow (add) userdn = "ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ipa,dc=test")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)' from aci, current value [] 2020-06-03T06:39:48Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ipa,dc=test")(version 3.0; acl "Allow services to create private container"; allow (add) userdn = "ldap:///krbprincipalname=($attr.cn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' from aci, current value [] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#USERDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' from aci, current value [] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect container owners can manage vaults in the container"; allow(read, search, compare, add, delete) userattr="parent[1].owner#GROUPDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' from aci, current value [] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' from aci, current value [] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' from aci, current value [] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#USERDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' from aci, current value [] 2020-06-03T06:39:48Z DEBUG remove: '(targetfilter="(objectClass=ipaVault)")(targetattr="*")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(read, search, compare, write) userattr="owner#GROUPDN";)' not in aci 2020-06-03T06:39:48Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test" and userattr="owner#SELFDN";)' from aci, current value [] 2020-06-03T06:39:48Z DEBUG remove: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test" and userattr="owner#SELFDN";)' not in aci 2020-06-03T06:39:48Z DEBUG addifexist: '(target="ldap:///cn=*,cn=users,cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow users to create private container"; allow(add) userdn="ldap:///uid=($attr.cn),cn=users,cn=accounts,dc=ipa,dc=test" and userattr="owner#SELFDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(target="ldap:///cn=*,cn=services,cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter="(objectClass=ipaVaultContainer)")(version 3.0; acl "Allow services to create private container"; allow(add) userdn="ldap:///krbprincipalname=($attr.cn),cn=services,cn=accounts,dc=ipa,dc=test" and userattr="owner#SELFDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Container owners can access the container"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description || owner")(version 3.0; acl "Indirect container owners can access the container"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Container owners can manage the container"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVaultContainer)")(targetattr="objectClass || cn || description")(version 3.0; acl "Indirect container owners can manage the container"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#USERDN" and userattr="owner#SELFDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(version 3.0; acl "Indirect container owners can add vaults in the container"; allow(add) userattr="parent[1].owner#GROUPDN" and userattr="owner#SELFDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault owners can access the vault"; allow(read, search, compare) userattr="owner#USERDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault owners can access the vault"; allow(read, search, compare) userattr="owner#GROUPDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Vault members can access the vault"; allow(read, search, compare) userattr="member#USERDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || owner || member")(version 3.0; acl "Indirect vault members can access the vault"; allow(read, search, compare) userattr="member#GROUPDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Vault owners can manage the vault"; allow(write, delete) userattr="owner#USERDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG addifexist: '(targetfilter="(objectClass=ipaVault)")(targetattr="objectClass || cn || description || ipaVaultType || ipaVaultSalt || ipaVaultPublicKey || member")(version 3.0; acl "Indirect vault owners can manage the vault"; allow(write, delete) userattr="owner#GROUPDN";)' to aci, current value [] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=vaults,cn=kra,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/40-vault.update 0.003 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/41-caacl.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=caacls,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=caacls,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG caacls 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Add CA ACL";allow (add) groupdn = "ldap:///cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Delete CA ACL";allow (delete) groupdn = "ldap:///cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "hostcategory || ipacacategory || ipacertprofilecategory || ipamemberca || ipamembercertprofile || memberhost || memberservice || memberuser || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Manage CA ACL Membership";allow (write) groupdn = "ldap:///cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipaenabledflag")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Modify CA ACL";allow (write) groupdn = "ldap:///cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipacacategory || ipacertprofilecategory || ipaenabledflag || ipamemberca || ipamembercertprofile || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Read CA ACLs";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=caacls,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG caacls 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Add CA ACL";allow (add) groupdn = "ldap:///cn=System: Add CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Delete CA ACL";allow (delete) groupdn = "ldap:///cn=System: Delete CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "hostcategory || ipacacategory || ipacertprofilecategory || ipamemberca || ipamembercertprofile || memberhost || memberservice || memberuser || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Manage CA ACL Membership";allow (write) groupdn = "ldap:///cn=System: Manage CA ACL Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description || ipaenabledflag")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Modify CA ACL";allow (write) groupdn = "ldap:///cn=System: Modify CA ACL,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || hostcategory || ipacacategory || ipacertprofilecategory || ipaenabledflag || ipamemberca || ipamembercertprofile || ipauniqueid || member || memberhost || memberservice || memberuser || modifytimestamp || objectclass || servicecategory || usercategory")(targetfilter = "(objectclass=ipacaacl)")(version 3.0;acl "permission:System: Read CA ACLs";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/41-caacl.update 0.002 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/41-lightweight-cas.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=cas,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=cas,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG cas 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Add CA";allow (add) groupdn = "ldap:///cn=System: Add CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Delete CA";allow (delete) groupdn = "ldap:///cn=System: Delete CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Modify CA";allow (write) groupdn = "ldap:///cn=System: Modify CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacaid || ipacaissuerdn || ipacasubjectdn || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Read CAs";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=cas,cn=ca,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG cas 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Add CA";allow (add) groupdn = "ldap:///cn=System: Add CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Delete CA";allow (delete) groupdn = "ldap:///cn=System: Delete CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || description")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Modify CA";allow (write) groupdn = "ldap:///cn=System: Modify CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipacaid || ipacaissuerdn || ipacasubjectdn || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaca)")(version 3.0;acl "permission:System: Read CAs";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/41-lightweight-cas.update 0.002 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/45-roles.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Modify Users and Reset passwords 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Modify Users and Reset passwords 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Modify Users and Reset passwords,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Modify Users and Reset passwords 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Modify Users and Reset passwords 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Modify Group membership,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Modify Group membership 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Modify Group membership 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Modify Group membership,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=helpdesk,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Modify Group membership 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Modify Group membership 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add User to default group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Stage User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Responsible for creating Users and Groups 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG User Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add User to default group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Stage User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Responsible for creating Users and Groups 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG User Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add User to default group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG User Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG User Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add User to default group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read UPG Definition,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG User Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG User Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Group Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Group Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify External Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Group Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Group Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Stage User Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Stage User Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Stage User Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read Radius Servers,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Preserved Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Stage User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Stage Users,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Stage User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove preserved User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Reset Preserved User password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=User Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Stage User Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Stage User Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Host Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Service Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Automount Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG IT Specialist 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IT Specialist 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Host Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Service Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Automount Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG IT Specialist 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IT Specialist 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Host Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Host Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Host Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Hosts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Host Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Host Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Host Group Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Host Group Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Host Group Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hostgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Hostgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Host Group Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Host Group Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Service Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Service Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Service Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Service Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Service Delegation Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Service Delegations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Service Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Service Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Automount Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Automount Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Automount Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Automount Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Keys,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Locations,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Automount Maps,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Automount Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Automount Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG IT Security Specialist 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IT Security Specialist 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG IT Security Specialist 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IT Security Specialist 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Netgroups Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Netgroups Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Netgroups Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Netgroup Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Netgroups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Netgroups Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Netgroups Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG HBAC Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG HBAC Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=HBAC Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Rule Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify HBAC Rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Services,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete HBAC Service Groups,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage HBAC Service Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG HBAC Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG HBAC Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Sudo Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Sudo Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG add: 'cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Sudo Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Sudo Command Group Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo Command Group,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Sudo rule,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=IT Security Specialist,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Sudo Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Sudo Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Delegation Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Security Architect 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Security Architect 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Delegation Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Security Architect 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Security Architect 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Role administration 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Delegation Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Delegation Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Modify Privilege Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Privileges,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Role Membership,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Remove Roles,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Role administration 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Delegation Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Replication Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Replication Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test', 'cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test', 'cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test', 'cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test', 'cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test', 'cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=ipaservers,cn=hostgroups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Replication Administrators 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Replication Administrators 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Write IPA Configuration,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Write IPA Configuration 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Password Policy Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Password Policy Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG add: 'cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Password Policy Administrator,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy costemplate,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=Security Architect,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Password Policy Administrator 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Password Policy Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Enrollment Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Enrollment Administrator responsible for client(host) enrollment 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Enrollment Administrator 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Host Enrollment 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Host Enrollment 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test' to member, current value ['cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test', 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test', 'cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Enrollment Administrator,cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Host Enrollment 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Host Enrollment 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/45-roles.update 0.069 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-7_bit_check.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=7-bit check,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG 7-bit check 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG Enforce 7-bit clean attribute values 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG NS7bitAttr 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG NS7bitAttr_Init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libattr-unique-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG betxnpreoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG 389 Project 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-pluginarg0: 2020-06-03T06:39:48Z DEBUG uid 2020-06-03T06:39:48Z DEBUG nsslapd-pluginarg1: 2020-06-03T06:39:48Z DEBUG mail 2020-06-03T06:39:48Z DEBUG nsslapd-pluginarg2: 2020-06-03T06:39:48Z DEBUG , 2020-06-03T06:39:48Z DEBUG nsslapd-pluginarg3: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG replace: userpassword not found, skipping 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=7-bit check,cn=plugins,cn=config 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG 7-bit check 2020-06-03T06:39:48Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:48Z DEBUG database 2020-06-03T06:39:48Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:48Z DEBUG Enforce 7-bit clean attribute values 2020-06-03T06:39:48Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:48Z DEBUG on 2020-06-03T06:39:48Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:48Z DEBUG NS7bitAttr 2020-06-03T06:39:48Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:48Z DEBUG NS7bitAttr_Init 2020-06-03T06:39:48Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:48Z DEBUG libattr-unique-plugin 2020-06-03T06:39:48Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:48Z DEBUG betxnpreoperation 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:48Z DEBUG 389 Project 2020-06-03T06:39:48Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:48Z DEBUG 1.4.1.18 2020-06-03T06:39:48Z DEBUG nsslapd-pluginarg0: 2020-06-03T06:39:48Z DEBUG uid 2020-06-03T06:39:48Z DEBUG nsslapd-pluginarg1: 2020-06-03T06:39:48Z DEBUG mail 2020-06-03T06:39:48Z DEBUG nsslapd-pluginarg2: 2020-06-03T06:39:48Z DEBUG , 2020-06-03T06:39:48Z DEBUG nsslapd-pluginarg3: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nsSlapdPlugin 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-7_bit_check.update 0.004 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-dogtag10-migration.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=aclResources,o=ipaca 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=aclResources,o=ipaca 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG aclResources 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG CertACLS 2020-06-03T06:39:48Z DEBUG resourceACLS: 2020-06-03T06:39:48Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2020-06-03T06:39:48Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2020-06-03T06:39:48Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2020-06-03T06:39:48Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2020-06-03T06:39:48Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2020-06-03T06:39:48Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2020-06-03T06:39:48Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2020-06-03T06:39:48Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2020-06-03T06:39:48Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2020-06-03T06:39:48Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2020-06-03T06:39:48Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2020-06-03T06:39:48Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2020-06-03T06:39:48Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2020-06-03T06:39:48Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2020-06-03T06:39:48Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2020-06-03T06:39:48Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2020-06-03T06:39:48Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2020-06-03T06:39:48Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2020-06-03T06:39:48Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2020-06-03T06:39:48Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2020-06-03T06:39:48Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2020-06-03T06:39:48Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2020-06-03T06:39:48Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2020-06-03T06:39:48Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2020-06-03T06:39:48Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2020-06-03T06:39:48Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2020-06-03T06:39:48Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2020-06-03T06:39:48Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2020-06-03T06:39:48Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2020-06-03T06:39:48Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2020-06-03T06:39:48Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2020-06-03T06:39:48Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2020-06-03T06:39:48Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2020-06-03T06:39:48Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2020-06-03T06:39:48Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2020-06-03T06:39:48Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2020-06-03T06:39:48Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2020-06-03T06:39:48Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2020-06-03T06:39:48Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2020-06-03T06:39:48Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2020-06-03T06:39:48Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2020-06-03T06:39:48Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2020-06-03T06:39:48Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2020-06-03T06:39:48Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2020-06-03T06:39:48Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2020-06-03T06:39:48Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2020-06-03T06:39:48Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2020-06-03T06:39:48Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2020-06-03T06:39:48Z DEBUG addifexist: 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities'] 2020-06-03T06:39:48Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2020-06-03T06:39:48Z DEBUG addifexist: 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout'] 2020-06-03T06:39:48Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2020-06-03T06:39:48Z DEBUG addifexist: 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations'] 2020-06-03T06:39:48Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2020-06-03T06:39:48Z DEBUG addifexist: 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations'] 2020-06-03T06:39:48Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2020-06-03T06:39:48Z DEBUG addifexist: 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations'] 2020-06-03T06:39:48Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2020-06-03T06:39:48Z DEBUG replace: certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group":Anybody is allowed to read domain.xml but only Subsystem group is allowed to modify the domain.xml not found, skipping 2020-06-03T06:39:48Z DEBUG replace: certServer.ca.connectorInfo:read,modify:allow (modify,read) group="Enterprise KRA Administrators":Only Enterprise Administrators are allowed to update the connector information not found, skipping 2020-06-03T06:39:48Z DEBUG addifexist: 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles' to resourceACLS, current value ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations'] 2020-06-03T06:39:48Z DEBUG addifexist: set resourceACLS to ['certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete', 'certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify', 'certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify', 'certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify', 'certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml', 'certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter', 'certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log', 'certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content', 'certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify', 'certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify', 'certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify', 'certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets', 'certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify', 'certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify', 'certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify', 'certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify', 'certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify', 'certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory', 'certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate', 'certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates', 'certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests', 'certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request', 'certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information', 'certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests', 'certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl', 'certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate', 'certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates', 'certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain', 'certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL', 'certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request', 'certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status', 'certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request', 'certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate', 'certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request', 'certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile', 'certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles', 'certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile', 'certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles', 'certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles', 'certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests', 'certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA', 'certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics', 'certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups', 'certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information', 'certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent', 'certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration.', 'certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration.', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests.', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities', 'certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities', 'certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles', 'certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities', 'certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout', 'certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations', 'certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations', 'certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations', 'certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations', 'certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=aclResources,o=ipaca 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG aclResources 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG CertACLS 2020-06-03T06:39:48Z DEBUG resourceACLS: 2020-06-03T06:39:48Z DEBUG certServer.general.configuration:read,modify,delete:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify,delete) group="Administrators":Administrators, auditors, and agents are allowed to read CMS general configuration but only administrators are allowed to modify and delete 2020-06-03T06:39:48Z DEBUG certServer.policy.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read policy configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.acl.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents and auditors are allowed to read ACL configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.log.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read the log configuration but only administrators are allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.securitydomain.domainxml:read,modify:allow (read) user="anybody";allow (modify) group="Subsystem Group" || group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Anybody is allowed to read domain.xml but only Subsystem group and Enterprise Administrators are allowed to modify the domain.xml 2020-06-03T06:39:48Z DEBUG certServer.log.configuration.fileName:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents" ;deny (modify) user=anybody:Nobody is allowed to modify a fileName parameter 2020-06-03T06:39:48Z DEBUG certServer.log.content.signedAudit:read:allow (read) group="Auditors":Only auditor is allowed to read the signed audit log 2020-06-03T06:39:48Z DEBUG certServer.log.content.system:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2020-06-03T06:39:48Z DEBUG certServer.log.content.transactions:read:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors":Administrators, auditors, and agents are allowed to read the log content 2020-06-03T06:39:48Z DEBUG certServer.ca.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read CA configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.auth.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read authentication configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.ocsp.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, Agents, and auditors are allowed to read ocsp configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.registry.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":this acl is shared by all admin servlets 2020-06-03T06:39:48Z DEBUG certServer.profile.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read profile configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.job.configuration:read,modify:allow (read) group="Administrators" || group="Certificate Manager Agents" || group="Registration Manager Agents" || group="Auditors";allow (modify) group="Administrators":Administrators, agents, and auditors are allowed to read job configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.publisher.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read publisher configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.kra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read DRM configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.ra.configuration:read,modify:allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager Agents" || group="Registration Manager Agents";allow (modify) group="Administrators":Administrators, auditors, and agents are allowed to read RA configuration but only administrators allowed to modify 2020-06-03T06:39:48Z DEBUG certServer.ca.directory:update:allow (update) group="Certificate Manager Agents":Certificate Manager agents may update directory 2020-06-03T06:39:48Z DEBUG certServer.ca.certificate:import,unrevoke,revoke,read:allow (import,unrevoke,revoke,read) group="Certificate Manager Agents":Certificate Manager agents may import,unrevoke,revoke,read a certificate 2020-06-03T06:39:48Z DEBUG certServer.ca.certificates:revoke,list:allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents revoke, list certificates 2020-06-03T06:39:48Z DEBUG certServer.ca.requests:list:allow (list) group="Certificate Manager Agents"|| group="Registration Manager Agents":Only certificate and registration manager agents list requests 2020-06-03T06:39:48Z DEBUG certServer.ca.request.enrollment:submit,read,execute,assign,unassign:allow (submit) user="anybody";allow (read,execute,assign,unassign) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read,execute,assign or unassign request 2020-06-03T06:39:48Z DEBUG certServer.ca.ocsp:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may read ocsp information 2020-06-03T06:39:48Z DEBUG certServer.ee.request.ocsp:submit:allow (submit) ipaddress=".*":Any clients can submit ocsp requests 2020-06-03T06:39:48Z DEBUG certServer.ca.crl:read,update:allow (read,update) group="Certificate Manager Agents":Certificate Manager agents may read or update crl 2020-06-03T06:39:48Z DEBUG certServer.ee.certificate:renew,revoke,read,import:allow (renew,revoke,read,import) user="anybody":Anybody may renew,import,revoke,read a certificate 2020-06-03T06:39:48Z DEBUG certServer.ee.certificates:revoke,list:allow (revoke,list) user="anybody":Anybody may revoke, list certificates 2020-06-03T06:39:48Z DEBUG certServer.ee.certchain:download,read:allow (download,read) user="anybody":Anybody may download a certificate chain 2020-06-03T06:39:48Z DEBUG certServer.ee.crl:read,add:allow (read,add) user="anybody":Anybody may add or retrieve CRL 2020-06-03T06:39:48Z DEBUG certServer.ee.request.enrollment:submit:allow (submit) user="anybody":Anybody may submit an enrollment request 2020-06-03T06:39:48Z DEBUG certServer.ee.requestStatus:read:allow (read) user="anybody":Anybody may read request status 2020-06-03T06:39:48Z DEBUG certServer.ee.request.revocation:submit:allow (submit) user="anybody":Anybody may submit a revocation request 2020-06-03T06:39:48Z DEBUG certServer.admin.certificate:import:allow (import) user="anybody":Any user may import a certificate 2020-06-03T06:39:48Z DEBUG certServer.admin.request.enrollment:submit,read,execute:allow (submit) user="anybody";allow (read,execute) group="Certificate Manager Agents":Anybody may submit an enrollment request, Certificate Manager Agents may read or execute request 2020-06-03T06:39:48Z DEBUG certServer.ca.request.profile:approve,read:allow (approve,read) group="Certificate Manager Agents":Certificate Manager agents may approve profile 2020-06-03T06:39:48Z DEBUG certServer.ca.profiles:list:allow (list) group="Certificate Manager Agents":Certificate Manager agents may list profiles 2020-06-03T06:39:48Z DEBUG certServer.ca.profile:read,approve:allow (read,approve) group="Certificate Manager Agents":Certificate Manager agents may read profile 2020-06-03T06:39:48Z DEBUG certServer.ee.profile:submit,read:allow (submit,read) user="anybody":Anybody may submit certificate profiles 2020-06-03T06:39:48Z DEBUG certServer.ee.profiles:list:allow (list) user="anybody":Anybody may list certificate profiles 2020-06-03T06:39:48Z DEBUG certServer.ca.connector:submit:allow (submit) group="Trusted Managers":Only Trusted Managers submit requests 2020-06-03T06:39:48Z DEBUG certServer.ca.clone:submit:allow (submit) group="Certificate Manager Agents":Certificate Manager Agents are allowed to submit request to the master CA 2020-06-03T06:39:48Z DEBUG certServer.ca.systemstatus:read:allow (read) group="Certificate Manager Agents":Certificate Manager agents may view statistics 2020-06-03T06:39:48Z DEBUG certServer.ca.group:read,modify:allow (modify,read) group="Administrators":Only administrators are allowed to read and modify users and groups 2020-06-03T06:39:48Z DEBUG certServer.ca.connectorInfo:read,modify:allow (read) group="Enterprise KRA Administrators";allow (modify) group="Enterprise KRA Administrators" || group="Subsystem Group":Only Enterprise Administrators and Subsystem Group are allowed to update the connector information 2020-06-03T06:39:48Z DEBUG certServer.ca.registerUser:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators" || group="Enterprise TPS Administrators":Only Enterprise Administrators are allowed to register a new agent 2020-06-03T06:39:48Z DEBUG certServer.clone.configuration:read,modify:allow (modify,read) group="Enterprise CA Administrators" || group="Enterprise KRA Administrators" || group="Enterprise RA Administrators" || group="Enterprise OCSP Administrators" || group="Enterprise TKS Administrators":Only Enterprise Administrators are allowed to clone the configuration. 2020-06-03T06:39:48Z DEBUG certServer.admin.ocsp:read,modify:allow (modify,read) group="Enterprise OCSP Administrators":Only Enterprise Administrators are allowed to read or update the OCSP configuration. 2020-06-03T06:39:48Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2020-06-03T06:39:48Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2020-06-03T06:39:48Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2020-06-03T06:39:48Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2020-06-03T06:39:48Z DEBUG certServer.ca.selftests:read,execute:allow (read,execute) group="Administrators":Only admins can access selftests. 2020-06-03T06:39:48Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2020-06-03T06:39:48Z DEBUG certServer.ca.authorities:list,read:allow (list,read) user="anybody":Anybody may list and read lightweight authorities 2020-06-03T06:39:48Z DEBUG certServer.ca.authorities:create,modify:allow (create,modify) group="Administrators":Administrators may create and modify lightweight authorities 2020-06-03T06:39:48Z DEBUG certServer.ca.authorities:delete:allow (delete) group="Administrators":Administrators may delete lightweight authorities 2020-06-03T06:39:48Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2020-06-03T06:39:48Z DEBUG certServer.ca.authorities:create,modify,delete:allow (create,modify,delete) group="Certificate Manager Agents":Certificate Manager Agents may manage lightweight authorities 2020-06-03T06:39:48Z DEBUG certServer.ca.account:login,logout:allow (login,logout) user="anybody":Anybody can login and logout 2020-06-03T06:39:48Z DEBUG certServer.ca.certrequests:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert request operations 2020-06-03T06:39:48Z DEBUG certServer.ca.certs:execute:allow (execute) group="Certificate Manager Agents":Agents may execute cert operations 2020-06-03T06:39:48Z DEBUG certServer.ca.groups:execute:allow (execute) group="Administrators":Admins may execute group operations 2020-06-03T06:39:48Z DEBUG certServer.ca.users:execute:allow (execute) group="Administrators":Admins may execute user operations 2020-06-03T06:39:48Z DEBUG certServer.profile.configuration:read,modify:allow (read,modify) group="Certificate Manager Agents":Certificate Manager agents may modify (create/update/delete) and read profiles 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-dogtag10-migration.update 0.011 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-groupuuid.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 3c66d416-a563-11ea-af72-0242ac120002 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG uid=admin,cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG gidNumber: 2020-06-03T06:39:48Z DEBUG 1853200000 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Account administrators group 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG admins 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG posixgroup 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG nestedGroup 2020-06-03T06:39:48Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'ipaobject', 'nestedGroup'] 2020-06-03T06:39:48Z DEBUG add: updated value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'nestedGroup', 'ipaobject'] 2020-06-03T06:39:48Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['3c66d416-a563-11ea-af72-0242ac120002'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=Replication Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Remove Replication Agreements,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Modify PassSync Managers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read LDBM Database Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Add Configuration Sub-Entries,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=Host Enrollment,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Add krbPrincipalName to a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Enroll a Host,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Enrollment Password,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Manage Host Principals,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 3c66d416-a563-11ea-af72-0242ac120002 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG uid=admin,cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG gidNumber: 2020-06-03T06:39:48Z DEBUG 1853200000 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Account administrators group 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG admins 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG posixgroup 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG nestedGroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ipausers,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 3c6803fe-a563-11ea-a623-0242ac120002 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipausers 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Default group for all users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'nestedgroup', 'ipausergroup', 'ipaobject'] 2020-06-03T06:39:48Z DEBUG add: updated value ['top', 'groupofnames', 'nestedgroup', 'ipausergroup', 'ipaobject'] 2020-06-03T06:39:48Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['3c6803fe-a563-11ea-a623-0242ac120002'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ipausers,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 3c6803fe-a563-11ea-a623-0242ac120002 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipausers 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Default group for all users 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=editors,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 3c683dd8-a563-11ea-9009-0242ac120002 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG editors 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Limited admins who can edit other users 2020-06-03T06:39:48Z DEBUG gidNumber: 2020-06-03T06:39:48Z DEBUG 1853200002 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG posixgroup 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG nestedGroup 2020-06-03T06:39:48Z DEBUG add: 'ipaobject' to objectclass, current value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'ipaobject', 'nestedGroup'] 2020-06-03T06:39:48Z DEBUG add: updated value ['top', 'groupofnames', 'posixgroup', 'ipausergroup', 'nestedGroup', 'ipaobject'] 2020-06-03T06:39:48Z DEBUG addifnew: 'autogenerate' to ipaUniqueID, current value ['3c683dd8-a563-11ea-9009-0242ac120002'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=editors,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 3c683dd8-a563-11ea-9009-0242ac120002 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG editors 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Limited admins who can edit other users 2020-06-03T06:39:48Z DEBUG gidNumber: 2020-06-03T06:39:48Z DEBUG 1853200002 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG posixgroup 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG nestedGroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-groupuuid.update 0.010 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-hbacservice.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=crond,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce43b42-a564-11ea-9261-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG crond 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG crond 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=crond,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce43b42-a564-11ea-9261-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG crond 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG crond 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=vsftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce4cecc-a564-11ea-842b-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG vsftpd 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG vsftpd 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=vsftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce4cecc-a564-11ea-842b-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG vsftpd 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG vsftpd 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=proftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce559d2-a564-11ea-89e8-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG proftpd 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG proftpd 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=proftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce559d2-a564-11ea-89e8-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG proftpd 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG proftpd 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce5dab0-a564-11ea-b994-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG pure-ftpd 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG pure-ftpd 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce5dab0-a564-11ea-b994-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG pure-ftpd 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG pure-ftpd 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=gssftp,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce65d0a-a564-11ea-ba26-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG gssftp 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG gssftp 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=gssftp,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce65d0a-a564-11ea-ba26-0242ac120002 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG gssftp 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG gssftp 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipahbacservice 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce70390-a564-11ea-99e8-0242ac120002 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Default group of ftp related services 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ftp 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG ipahbacservicegroup 2020-06-03T06:39:48Z DEBUG nestedGroup 2020-06-03T06:39:48Z DEBUG groupOfNames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ftp,cn=hbacservicegroups,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0ce70390-a564-11ea-99e8-0242ac120002 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=ftp,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=proftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=pure-ftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=vsftpd,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=gssftp,cn=hbacservices,cn=hbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Default group of ftp related services 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ftp 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG ipahbacservicegroup 2020-06-03T06:39:48Z DEBUG nestedGroup 2020-06-03T06:39:48Z DEBUG groupOfNames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-hbacservice.update 0.014 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-ipaconfig.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ipaConfig,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaKrbAuthzData: 2020-06-03T06:39:48Z DEBUG MS-PAC 2020-06-03T06:39:48Z DEBUG nfs:NONE 2020-06-03T06:39:48Z DEBUG ipaCertificateSubjectBase: 2020-06-03T06:39:48Z DEBUG O=IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipaConfig 2020-06-03T06:39:48Z DEBUG ipaSELinuxUserMapDefault: 2020-06-03T06:39:48Z DEBUG generic_u:s0-s3:c0.c15 2020-06-03T06:39:48Z DEBUG ipaSELinuxUserMapOrder: 2020-06-03T06:39:48Z DEBUG generic_u3:s3-s3:c0.c15$generic_u2:s2-s3:c0.c15$generic_u1:s1-s3:c0.c15$officer_u:s0-s3:c0.c15$generic_u:s0-s3:c0.c15 2020-06-03T06:39:48Z DEBUG ipaConfigString: 2020-06-03T06:39:48Z DEBUG AllowNThash 2020-06-03T06:39:48Z DEBUG KDC:Disable Last Success 2020-06-03T06:39:48Z DEBUG ipaMigrationEnabled: 2020-06-03T06:39:48Z DEBUG FALSE 2020-06-03T06:39:48Z DEBUG ipaDefaultEmailDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG ipaUserObjectClasses: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG person 2020-06-03T06:39:48Z DEBUG organizationalperson 2020-06-03T06:39:48Z DEBUG inetorgperson 2020-06-03T06:39:48Z DEBUG inetuser 2020-06-03T06:39:48Z DEBUG posixaccount 2020-06-03T06:39:48Z DEBUG krbprincipalaux 2020-06-03T06:39:48Z DEBUG krbticketpolicyaux 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG ipasshuser 2020-06-03T06:39:48Z DEBUG ipaGroupObjectClasses: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG ipaPwdExpAdvNotify: 2020-06-03T06:39:48Z DEBUG 4 2020-06-03T06:39:48Z DEBUG ipaMaxHostnameLength: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG ipaMaxUsernameLength: 2020-06-03T06:39:48Z DEBUG 32 2020-06-03T06:39:48Z DEBUG ipaDefaultPrimaryGroup: 2020-06-03T06:39:48Z DEBUG ipausers 2020-06-03T06:39:48Z DEBUG ipaDefaultLoginShell: 2020-06-03T06:39:48Z DEBUG /bin/bash 2020-06-03T06:39:48Z DEBUG ipaHomesRootDir: 2020-06-03T06:39:48Z DEBUG /home 2020-06-03T06:39:48Z DEBUG ipaSearchRecordsLimit: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG ipaSearchTimeLimit: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG ipaGroupSearchFields: 2020-06-03T06:39:48Z DEBUG cn,description 2020-06-03T06:39:48Z DEBUG ipaUserSearchFields: 2020-06-03T06:39:48Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG ipaGuiConfig 2020-06-03T06:39:48Z DEBUG ipaConfigObject 2020-06-03T06:39:48Z DEBUG ipaUserAuthTypeClass 2020-06-03T06:39:48Z DEBUG ipaNameResolutionData 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxhostnamelength || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG replace: ipaSELinuxUserMapOrder: officer_u:s0-s3:c0.c15$generic3_u:s3-s3:c0.c15$generic_u2:s2-s3:c0.c15$generic_u1:s1-s3:c0.c15$generic_u:s0-s3:c0.c15 not found, skipping 2020-06-03T06:39:48Z DEBUG replace: officer_u:s0-s3:c0.c15$generic3_u:s3-s3:c0.c15$generic_u2:s2-s3:c0.c15$generic_u1:s1-s3:c0.c15$generic_u:s0-s3:c0.c15 not found, skipping 2020-06-03T06:39:48Z DEBUG add: 'generic_u:s0-s3:c0.c15' to ipaSELinuxUserMapDefault, current value ['generic_u:s0-s3:c0.c15'] 2020-06-03T06:39:48Z DEBUG add: updated value ['generic_u:s0-s3:c0.c15'] 2020-06-03T06:39:48Z DEBUG add: 'ipasshuser' to ipaUserObjectClasses, current value ['top', 'person', 'organizationalperson', 'inetorgperson', 'inetuser', 'posixaccount', 'krbprincipalaux', 'krbticketpolicyaux', 'ipaobject', 'ipasshuser'] 2020-06-03T06:39:48Z DEBUG add: updated value ['top', 'person', 'organizationalperson', 'inetorgperson', 'inetuser', 'posixaccount', 'krbprincipalaux', 'krbticketpolicyaux', 'ipaobject', 'ipasshuser'] 2020-06-03T06:39:48Z DEBUG remove: 'AllowLMhash' from ipaConfigString, current value ['AllowNThash', 'KDC:Disable Last Success'] 2020-06-03T06:39:48Z DEBUG remove: 'AllowLMhash' not in ipaConfigString 2020-06-03T06:39:48Z DEBUG add: 'ipaUserAuthTypeClass' to objectClass, current value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass', 'ipaNameResolutionData'] 2020-06-03T06:39:48Z DEBUG add: updated value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaNameResolutionData', 'ipaUserAuthTypeClass'] 2020-06-03T06:39:48Z DEBUG add: 'ipaNameResolutionData' to objectClass, current value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaNameResolutionData', 'ipaUserAuthTypeClass'] 2020-06-03T06:39:48Z DEBUG add: updated value ['nsContainer', 'top', 'ipaGuiConfig', 'ipaConfigObject', 'ipaUserAuthTypeClass', 'ipaNameResolutionData'] 2020-06-03T06:39:48Z DEBUG addifnew: '64' to ipamaxhostnamelength, current value ['64'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ipaConfig,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaKrbAuthzData: 2020-06-03T06:39:48Z DEBUG MS-PAC 2020-06-03T06:39:48Z DEBUG nfs:NONE 2020-06-03T06:39:48Z DEBUG ipaCertificateSubjectBase: 2020-06-03T06:39:48Z DEBUG O=IPA.TEST 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ipaConfig 2020-06-03T06:39:48Z DEBUG ipaSELinuxUserMapDefault: 2020-06-03T06:39:48Z DEBUG generic_u:s0-s3:c0.c15 2020-06-03T06:39:48Z DEBUG ipaSELinuxUserMapOrder: 2020-06-03T06:39:48Z DEBUG generic_u3:s3-s3:c0.c15$generic_u2:s2-s3:c0.c15$generic_u1:s1-s3:c0.c15$officer_u:s0-s3:c0.c15$generic_u:s0-s3:c0.c15 2020-06-03T06:39:48Z DEBUG ipaConfigString: 2020-06-03T06:39:48Z DEBUG AllowNThash 2020-06-03T06:39:48Z DEBUG KDC:Disable Last Success 2020-06-03T06:39:48Z DEBUG ipaMigrationEnabled: 2020-06-03T06:39:48Z DEBUG FALSE 2020-06-03T06:39:48Z DEBUG ipaDefaultEmailDomain: 2020-06-03T06:39:48Z DEBUG ipa.test 2020-06-03T06:39:48Z DEBUG ipaUserObjectClasses: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG person 2020-06-03T06:39:48Z DEBUG organizationalperson 2020-06-03T06:39:48Z DEBUG inetorgperson 2020-06-03T06:39:48Z DEBUG inetuser 2020-06-03T06:39:48Z DEBUG posixaccount 2020-06-03T06:39:48Z DEBUG krbprincipalaux 2020-06-03T06:39:48Z DEBUG krbticketpolicyaux 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG ipasshuser 2020-06-03T06:39:48Z DEBUG ipaGroupObjectClasses: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG ipaPwdExpAdvNotify: 2020-06-03T06:39:48Z DEBUG 4 2020-06-03T06:39:48Z DEBUG ipaMaxHostnameLength: 2020-06-03T06:39:48Z DEBUG 64 2020-06-03T06:39:48Z DEBUG ipaMaxUsernameLength: 2020-06-03T06:39:48Z DEBUG 32 2020-06-03T06:39:48Z DEBUG ipaDefaultPrimaryGroup: 2020-06-03T06:39:48Z DEBUG ipausers 2020-06-03T06:39:48Z DEBUG ipaDefaultLoginShell: 2020-06-03T06:39:48Z DEBUG /bin/bash 2020-06-03T06:39:48Z DEBUG ipaHomesRootDir: 2020-06-03T06:39:48Z DEBUG /home 2020-06-03T06:39:48Z DEBUG ipaSearchRecordsLimit: 2020-06-03T06:39:48Z DEBUG 100 2020-06-03T06:39:48Z DEBUG ipaSearchTimeLimit: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG ipaGroupSearchFields: 2020-06-03T06:39:48Z DEBUG cn,description 2020-06-03T06:39:48Z DEBUG ipaUserSearchFields: 2020-06-03T06:39:48Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG nsContainer 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG ipaGuiConfig 2020-06-03T06:39:48Z DEBUG ipaConfigObject 2020-06-03T06:39:48Z DEBUG ipaUserAuthTypeClass 2020-06-03T06:39:48Z DEBUG ipaNameResolutionData 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxhostnamelength || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-ipaconfig.update 0.007 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-krbenctypes.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG krbMKey: 2020-06-03T06:39:48Z DEBUG XXXXXXXX 2020-06-03T06:39:48Z DEBUG krbDefaultEncSaltTypes: 2020-06-03T06:39:48Z DEBUG aes256-cts:special 2020-06-03T06:39:48Z DEBUG aes128-cts:special 2020-06-03T06:39:48Z DEBUG krbMaxRenewableAge: 2020-06-03T06:39:48Z DEBUG 604800 2020-06-03T06:39:48Z DEBUG krbMaxTicketLife: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG krbSupportedEncSaltTypes: 2020-06-03T06:39:48Z DEBUG aes256-cts:normal 2020-06-03T06:39:48Z DEBUG aes256-cts:special 2020-06-03T06:39:48Z DEBUG aes128-cts:normal 2020-06-03T06:39:48Z DEBUG aes128-cts:special 2020-06-03T06:39:48Z DEBUG aes128-sha2:normal 2020-06-03T06:39:48Z DEBUG aes128-sha2:special 2020-06-03T06:39:48Z DEBUG aes256-sha2:normal 2020-06-03T06:39:48Z DEBUG aes256-sha2:special 2020-06-03T06:39:48Z DEBUG camellia128-cts-cmac:normal 2020-06-03T06:39:48Z DEBUG camellia128-cts-cmac:special 2020-06-03T06:39:48Z DEBUG camellia256-cts-cmac:normal 2020-06-03T06:39:48Z DEBUG camellia256-cts-cmac:special 2020-06-03T06:39:48Z DEBUG krbSearchScope: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG krbSubTrees: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG krbrealmcontainer 2020-06-03T06:39:48Z DEBUG krbticketpolicyaux 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA.TEST 2020-06-03T06:39:48Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:48Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || krbauthindmaxrenewableage || krbauthindmaxticketlife || krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticketlife || krbsupportedencsalttypes || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read Default Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Add Group Password Policy";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Delete Group Password Policy";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Modify Group Password Policy";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || cospriority || createtimestamp || entryusn || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Read Group Password Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG add: 'camellia128-cts-cmac:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2020-06-03T06:39:48Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal'] 2020-06-03T06:39:48Z DEBUG add: 'camellia128-cts-cmac:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal'] 2020-06-03T06:39:48Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special'] 2020-06-03T06:39:48Z DEBUG add: 'camellia256-cts-cmac:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special'] 2020-06-03T06:39:48Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal'] 2020-06-03T06:39:48Z DEBUG add: 'camellia256-cts-cmac:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia256-cts-cmac:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal'] 2020-06-03T06:39:48Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2020-06-03T06:39:48Z DEBUG add: 'aes128-sha2:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special'] 2020-06-03T06:39:48Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal'] 2020-06-03T06:39:48Z DEBUG add: 'aes128-sha2:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal'] 2020-06-03T06:39:48Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special'] 2020-06-03T06:39:48Z DEBUG add: 'aes256-sha2:normal' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:normal', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special'] 2020-06-03T06:39:48Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal'] 2020-06-03T06:39:48Z DEBUG add: 'aes256-sha2:special' to krbSupportedEncSaltTypes, current value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'aes256-sha2:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal'] 2020-06-03T06:39:48Z DEBUG add: updated value ['aes256-cts:normal', 'aes256-cts:special', 'aes128-cts:normal', 'aes128-cts:special', 'camellia128-cts-cmac:normal', 'camellia128-cts-cmac:special', 'camellia256-cts-cmac:normal', 'camellia256-cts-cmac:special', 'aes128-sha2:normal', 'aes128-sha2:special', 'aes256-sha2:normal', 'aes256-sha2:special'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG krbMKey: 2020-06-03T06:39:48Z DEBUG XXXXXXXX 2020-06-03T06:39:48Z DEBUG krbDefaultEncSaltTypes: 2020-06-03T06:39:48Z DEBUG aes256-cts:special 2020-06-03T06:39:48Z DEBUG aes128-cts:special 2020-06-03T06:39:48Z DEBUG krbMaxRenewableAge: 2020-06-03T06:39:48Z DEBUG 604800 2020-06-03T06:39:48Z DEBUG krbMaxTicketLife: 2020-06-03T06:39:48Z DEBUG 86400 2020-06-03T06:39:48Z DEBUG krbSupportedEncSaltTypes: 2020-06-03T06:39:48Z DEBUG aes256-cts:normal 2020-06-03T06:39:48Z DEBUG aes256-cts:special 2020-06-03T06:39:48Z DEBUG aes128-cts:normal 2020-06-03T06:39:48Z DEBUG aes128-cts:special 2020-06-03T06:39:48Z DEBUG camellia128-cts-cmac:normal 2020-06-03T06:39:48Z DEBUG camellia128-cts-cmac:special 2020-06-03T06:39:48Z DEBUG camellia256-cts-cmac:normal 2020-06-03T06:39:48Z DEBUG camellia256-cts-cmac:special 2020-06-03T06:39:48Z DEBUG aes128-sha2:normal 2020-06-03T06:39:48Z DEBUG aes128-sha2:special 2020-06-03T06:39:48Z DEBUG aes256-sha2:normal 2020-06-03T06:39:48Z DEBUG aes256-sha2:special 2020-06-03T06:39:48Z DEBUG krbSearchScope: 2020-06-03T06:39:48Z DEBUG 2 2020-06-03T06:39:48Z DEBUG krbSubTrees: 2020-06-03T06:39:48Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG krbrealmcontainer 2020-06-03T06:39:48Z DEBUG krbticketpolicyaux 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA.TEST 2020-06-03T06:39:48Z DEBUG krbPwdPolicyReference: 2020-06-03T06:39:48Z DEBUG cn=Default Kerberos Service Password Policy,cn=Kerberos Service Password Policy,cn=IPA.TEST,cn=kerberos,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG aci: 2020-06-03T06:39:48Z DEBUG (targetattr = "createtimestamp || entryusn || krbauthindmaxrenewableage || krbauthindmaxticketlife || krbdefaultencsalttypes || krbmaxrenewableage || krbmaxticketlife || krbsupportedencsalttypes || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read Default Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Default Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Add Group Password Policy";allow (add) groupdn = "ldap:///cn=System: Add Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Delete Group Password Policy";allow (delete) groupdn = "ldap:///cn=System: Delete Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Modify Group Password Policy";allow (write) groupdn = "ldap:///cn=System: Modify Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG (targetattr = "cn || cospriority || createtimestamp || entryusn || krbmaxpwdlife || krbminpwdlife || krbpwdfailurecountinterval || krbpwdhistorylength || krbpwdlockoutduration || krbpwdmaxfailure || krbpwdmindiffchars || krbpwdminlength || modifytimestamp || objectclass")(targetfilter = "(objectclass=krbpwdpolicy)")(version 3.0;acl "permission:System: Read Group Password Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Group Password Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-krbenctypes.update 0.006 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/50-nis.update' 2020-06-03T06:39:48Z DEBUG Executing upgrade plugin: update_nis_configuration 2020-06-03T06:39:48Z DEBUG raw: update_nis_configuration 2020-06-03T06:39:48Z DEBUG Skipping NIS update, NIS Server is not configured 2020-06-03T06:39:48Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:48Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/50-nis.update 0.002 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/55-pbacmemberof.update' 2020-06-03T06:39:48Z DEBUG New entry: cn=Update PBAC memberOf 138104591,cn=memberof task,cn=tasks,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Update PBAC memberOf 138104591,cn=memberof task,cn=tasks,cn=config 2020-06-03T06:39:48Z DEBUG add: 'top' to objectClass, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['top'] 2020-06-03T06:39:48Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2020-06-03T06:39:48Z DEBUG add: updated value ['top', 'extensibleObject'] 2020-06-03T06:39:48Z DEBUG add: 'IPA PBAC memberOf 138104591' to cn, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['IPA PBAC memberOf 138104591'] 2020-06-03T06:39:48Z DEBUG add: 'cn=privileges,cn=pbac,dc=ipa,dc=test' to basedn, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=privileges,cn=pbac,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: '(objectclass=*)' to filter, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['(objectclass=*)'] 2020-06-03T06:39:48Z DEBUG add: '10' to ttl, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['10'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Update PBAC memberOf 138104591,cn=memberof task,cn=tasks,cn=config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG IPA PBAC memberOf 138104591 2020-06-03T06:39:48Z DEBUG basedn: 2020-06-03T06:39:48Z DEBUG cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG filter: 2020-06-03T06:39:48Z DEBUG (objectclass=*) 2020-06-03T06:39:48Z DEBUG ttl: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG New entry: cn=Update Role memberOf 138104591,cn=memberof task,cn=tasks,cn=config 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=Update Role memberOf 138104591,cn=memberof task,cn=tasks,cn=config 2020-06-03T06:39:48Z DEBUG add: 'top' to objectClass, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['top'] 2020-06-03T06:39:48Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2020-06-03T06:39:48Z DEBUG add: updated value ['top', 'extensibleObject'] 2020-06-03T06:39:48Z DEBUG add: 'Update Role memberOf 138104591' to cn, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['Update Role memberOf 138104591'] 2020-06-03T06:39:48Z DEBUG add: 'cn=roles,cn=accounts,dc=ipa,dc=test' to basedn, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['cn=roles,cn=accounts,dc=ipa,dc=test'] 2020-06-03T06:39:48Z DEBUG add: '(objectclass=*)' to filter, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['(objectclass=*)'] 2020-06-03T06:39:48Z DEBUG add: '10' to ttl, current value [] 2020-06-03T06:39:48Z DEBUG add: updated value ['10'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=Update Role memberOf 138104591,cn=memberof task,cn=tasks,cn=config 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG extensibleObject 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG Update Role memberOf 138104591 2020-06-03T06:39:48Z DEBUG basedn: 2020-06-03T06:39:48Z DEBUG cn=roles,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG filter: 2020-06-03T06:39:48Z DEBUG (objectclass=*) 2020-06-03T06:39:48Z DEBUG ttl: 2020-06-03T06:39:48Z DEBUG 10 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/55-pbacmemberof.update 0.114 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/59-trusts-sysacount.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ADTrust Agents,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG adtrust agents 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG GroupOfNames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG add: 'nestedgroup' to objectClass, current value ['GroupOfNames', 'top', 'nestedgroup'] 2020-06-03T06:39:48Z DEBUG add: updated value ['GroupOfNames', 'top', 'nestedgroup'] 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=ADTrust Agents,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG adtrust agents 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG GroupOfNames 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG LDAP update duration: /usr/share/ipa/updates/59-trusts-sysacount.update 0.002 sec 2020-06-03T06:39:48Z DEBUG Parsing update file '/usr/share/ipa/updates/60-trusts.update' 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0cf2dd32-a564-11ea-b994-0242ac120002 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG uid=admin,cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Trusts administrators group 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG trust admins 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG ipaUniqueID: 2020-06-03T06:39:48Z DEBUG 0cf2dd32-a564-11ea-b994-0242ac120002 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG uid=admin,cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG Trusts administrators group 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG trust admins 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG ipausergroup 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG ipaobject 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:48Z DEBUG Updating existing entry: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Initial value 2020-06-03T06:39:48Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG System accounts able to access trust information 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ADTrust Agents 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG --------------------------------------------- 2020-06-03T06:39:48Z DEBUG Final value after applying updates 2020-06-03T06:39:48Z DEBUG dn: cn=ADTrust Agents,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG memberOf: 2020-06-03T06:39:48Z DEBUG cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG member: 2020-06-03T06:39:48Z DEBUG cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:48Z DEBUG description: 2020-06-03T06:39:48Z DEBUG System accounts able to access trust information 2020-06-03T06:39:48Z DEBUG cn: 2020-06-03T06:39:48Z DEBUG ADTrust Agents 2020-06-03T06:39:48Z DEBUG objectClass: 2020-06-03T06:39:48Z DEBUG top 2020-06-03T06:39:48Z DEBUG groupofnames 2020-06-03T06:39:48Z DEBUG nestedgroup 2020-06-03T06:39:48Z DEBUG [] 2020-06-03T06:39:48Z DEBUG Updated 0 2020-06-03T06:39:48Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=trusts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=trusts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG trusts 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:49Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=trusts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG trusts 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:49Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=trusts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=trusts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG trusts 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:49Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG add: '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)' to aci, current value ['(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-03T06:39:49Z DEBUG add: '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)' to aci, current value ['(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)' to aci, current value ['(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG replace: updated value ['(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG replace: (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";) not found, skipping 2020-06-03T06:39:49Z DEBUG add: '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)' to aci, current value ['(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)' to aci, current value ['(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";)', '(targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=trusts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG trusts 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipantadditionalsuffixes || ipantflatname || ipantsecurityidentifier || ipantsidblacklistincoming || ipantsidblacklistoutgoing || ipanttrustdirection || ipanttrusteddomainsid || ipanttrustpartner || modifytimestamp || objectclass")(version 3.0;acl "permission:System: Read Trust Information";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "gidnumber || krbprincipalname || uidnumber")(version 3.0;acl "permission:System: Read system trust accounts";allow (compare,read,search) groupdn = "ldap:///cn=System: Read system trust accounts,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="ipaProtectedOperation;read_keys")(version 3.0; acl "Allow trust agents to retrieve keytab keys for cross realm principals"; allow(read) userattr="ipaAllowedToPerform;read_keys#GROUPDN";) 2020-06-03T06:39:49Z DEBUG (targetattr="ipaProtectedOperation;write_keys")(version 3.0; acl "Allow trust agents to set keys for cross realm principals"; allow(write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing || krbPrincipalName || krbLastPwdChange || krbTicketFlags || krbLoginFailedCount || krbExtraData || krbPrincipalKey")(version 3.0;acl "Allow trust system user to create and delete trust accounts and cross realm principals"; allow (read,write,add,delete) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=trusts,dc=ipa,dc=test")(targetattr = "ipaNTTrustType || ipaNTTrustAttributes || ipaNTTrustDirection || ipaNTTrustPartner || ipaNTFlatName || ipaNTTrustAuthOutgoing || ipaNTTrustAuthIncoming || ipaNTSecurityIdentifier || ipaNTTrustForestTrustInfo || ipaNTTrustPosixOffset || ipaNTSupportedEncryptionTypes || ipaNTSIDBlacklistIncoming || ipaNTSIDBlacklistOutgoing")(version 3.0;acl "Allow trust admins manage trust accounts"; allow (read,write,add,delete) groupdn="ldap:///cn=trust admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "Allow reading POSIX information about trusted domain objects";allow (compare,read,search) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG associatedDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG nisDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG info: 2020-06-03T06:39:49Z DEBUG IPA V2.0 2020-06-03T06:39:49Z DEBUG dc: 2020-06-03T06:39:49Z DEBUG ipa 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG domain 2020-06-03T06:39:49Z DEBUG pilotObject 2020-06-03T06:39:49Z DEBUG domainRelatedObject 2020-06-03T06:39:49Z DEBUG nisDomainObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG add: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)' from aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG remove: '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read NT passwords"; allow (read) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)' not in aci 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG associatedDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG nisDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG info: 2020-06-03T06:39:49Z DEBUG IPA V2.0 2020-06-03T06:39:49Z DEBUG dc: 2020-06-03T06:39:49Z DEBUG ipa 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG domain 2020-06-03T06:39:49Z DEBUG pilotObject 2020-06-03T06:39:49Z DEBUG domainRelatedObject 2020-06-03T06:39:49Z DEBUG nisDomainObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG services 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";) 2020-06-03T06:39:49Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG add: '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)'] 2020-06-03T06:39:49Z DEBUG add: '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)' to aci, current value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";)', '(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)', '(target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";)'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=services,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG services 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "krbPrincipalKey || krbLastPwdChange")(target = "ldap:///krbprincipalname=*,cn=services,cn=accounts,dc=ipa,dc=test")(version 3.0;acl "Admins can manage service keytab";allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="userCertificate || krbPrincipalKey")(version 3.0; acl "Hosts can manage service Certificates and kerberos keys"; allow(write) userattr = "parent[0,1].managedby#USERDN";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can add own services"; allow(add) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///krbprincipalname=*/($dn)@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaService)")(version 3.0;acl "Hosts can delete own services"; allow(delete) userdn="ldap:///fqdn=($dn),cn=computers,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Add Services";allow (add) groupdn = "ldap:///cn=System: Add Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krblastpwdchange || krbprincipalkey")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab";allow (write) groupdn = "ldap:///cn=System: Manage Service Keytab,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || ipaallowedtoperform;read_keys || ipaallowedtoperform;write_keys || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Keytab Permissions";allow (compare,read,search,write) groupdn = "ldap:///cn=System: Manage Service Keytab Permissions,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Manage Service Principals";allow (write) groupdn = "ldap:///cn=System: Manage Service Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbprincipalauthind || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Modify Services";allow (write) groupdn = "ldap:///cn=System: Modify Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || ipantsecurityidentifier || loginshell || modifytimestamp || objectclass || uid || uidnumber")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read POSIX details of SMB services";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || ipakrbauthzdata || ipakrbprincipalalias || ipauniqueid || krbcanonicalname || krblastpwdchange || krbobjectreferences || krbpasswordexpiration || krbprincipalaliases || krbprincipalauthind || krbprincipalexpiration || krbprincipalname || managedby || memberof || modifytimestamp || objectclass || usercertificate")(targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Read Services";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=ipaservice)")(version 3.0;acl "permission:System: Remove Services";allow (delete) groupdn = "ldap:///cn=System: Remove Services,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targetattr="ipaNTHash")(version 3.0; acl "CIFS service can modify own ipaNTHash"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";) 2020-06-03T06:39:49Z DEBUG (target="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test")(targattrfilters="add=objectClass:(objectClass=ipaNTUserAttrs)")(version 3.0; acl "CIFS service can add ipaNTUserAttrs to itself"; allow(write) userdn="ldap:///krbprincipalname=cifs/($dn),cn=services,cn=accounts,dc=ipa,dc=test" or userattr="managedby#SELFDN";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=ipaConfig,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=ipaConfig,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG ipaKrbAuthzData: 2020-06-03T06:39:49Z DEBUG MS-PAC 2020-06-03T06:39:49Z DEBUG nfs:NONE 2020-06-03T06:39:49Z DEBUG ipaCertificateSubjectBase: 2020-06-03T06:39:49Z DEBUG O=IPA.TEST 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ipaConfig 2020-06-03T06:39:49Z DEBUG ipaSELinuxUserMapDefault: 2020-06-03T06:39:49Z DEBUG generic_u:s0-s3:c0.c15 2020-06-03T06:39:49Z DEBUG ipaSELinuxUserMapOrder: 2020-06-03T06:39:49Z DEBUG generic_u3:s3-s3:c0.c15$generic_u2:s2-s3:c0.c15$generic_u1:s1-s3:c0.c15$officer_u:s0-s3:c0.c15$generic_u:s0-s3:c0.c15 2020-06-03T06:39:49Z DEBUG ipaConfigString: 2020-06-03T06:39:49Z DEBUG AllowNThash 2020-06-03T06:39:49Z DEBUG KDC:Disable Last Success 2020-06-03T06:39:49Z DEBUG ipaMigrationEnabled: 2020-06-03T06:39:49Z DEBUG FALSE 2020-06-03T06:39:49Z DEBUG ipaDefaultEmailDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG ipaUserObjectClasses: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG person 2020-06-03T06:39:49Z DEBUG organizationalperson 2020-06-03T06:39:49Z DEBUG inetorgperson 2020-06-03T06:39:49Z DEBUG inetuser 2020-06-03T06:39:49Z DEBUG posixaccount 2020-06-03T06:39:49Z DEBUG krbprincipalaux 2020-06-03T06:39:49Z DEBUG krbticketpolicyaux 2020-06-03T06:39:49Z DEBUG ipaobject 2020-06-03T06:39:49Z DEBUG ipasshuser 2020-06-03T06:39:49Z DEBUG ipaGroupObjectClasses: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG groupofnames 2020-06-03T06:39:49Z DEBUG nestedgroup 2020-06-03T06:39:49Z DEBUG ipausergroup 2020-06-03T06:39:49Z DEBUG ipaobject 2020-06-03T06:39:49Z DEBUG ipaPwdExpAdvNotify: 2020-06-03T06:39:49Z DEBUG 4 2020-06-03T06:39:49Z DEBUG ipaMaxHostnameLength: 2020-06-03T06:39:49Z DEBUG 64 2020-06-03T06:39:49Z DEBUG ipaMaxUsernameLength: 2020-06-03T06:39:49Z DEBUG 32 2020-06-03T06:39:49Z DEBUG ipaDefaultPrimaryGroup: 2020-06-03T06:39:49Z DEBUG ipausers 2020-06-03T06:39:49Z DEBUG ipaDefaultLoginShell: 2020-06-03T06:39:49Z DEBUG /bin/bash 2020-06-03T06:39:49Z DEBUG ipaHomesRootDir: 2020-06-03T06:39:49Z DEBUG /home 2020-06-03T06:39:49Z DEBUG ipaSearchRecordsLimit: 2020-06-03T06:39:49Z DEBUG 100 2020-06-03T06:39:49Z DEBUG ipaSearchTimeLimit: 2020-06-03T06:39:49Z DEBUG 2 2020-06-03T06:39:49Z DEBUG ipaGroupSearchFields: 2020-06-03T06:39:49Z DEBUG cn,description 2020-06-03T06:39:49Z DEBUG ipaUserSearchFields: 2020-06-03T06:39:49Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG ipaGuiConfig 2020-06-03T06:39:49Z DEBUG ipaConfigObject 2020-06-03T06:39:49Z DEBUG ipaUserAuthTypeClass 2020-06-03T06:39:49Z DEBUG ipaNameResolutionData 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxhostnamelength || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG addifnew: 'MS-PAC' to ipaKrbAuthzData, current value ['MS-PAC', 'nfs:NONE'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=ipaConfig,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG ipaKrbAuthzData: 2020-06-03T06:39:49Z DEBUG MS-PAC 2020-06-03T06:39:49Z DEBUG nfs:NONE 2020-06-03T06:39:49Z DEBUG ipaCertificateSubjectBase: 2020-06-03T06:39:49Z DEBUG O=IPA.TEST 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ipaConfig 2020-06-03T06:39:49Z DEBUG ipaSELinuxUserMapDefault: 2020-06-03T06:39:49Z DEBUG generic_u:s0-s3:c0.c15 2020-06-03T06:39:49Z DEBUG ipaSELinuxUserMapOrder: 2020-06-03T06:39:49Z DEBUG generic_u3:s3-s3:c0.c15$generic_u2:s2-s3:c0.c15$generic_u1:s1-s3:c0.c15$officer_u:s0-s3:c0.c15$generic_u:s0-s3:c0.c15 2020-06-03T06:39:49Z DEBUG ipaConfigString: 2020-06-03T06:39:49Z DEBUG AllowNThash 2020-06-03T06:39:49Z DEBUG KDC:Disable Last Success 2020-06-03T06:39:49Z DEBUG ipaMigrationEnabled: 2020-06-03T06:39:49Z DEBUG FALSE 2020-06-03T06:39:49Z DEBUG ipaDefaultEmailDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG ipaUserObjectClasses: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG person 2020-06-03T06:39:49Z DEBUG organizationalperson 2020-06-03T06:39:49Z DEBUG inetorgperson 2020-06-03T06:39:49Z DEBUG inetuser 2020-06-03T06:39:49Z DEBUG posixaccount 2020-06-03T06:39:49Z DEBUG krbprincipalaux 2020-06-03T06:39:49Z DEBUG krbticketpolicyaux 2020-06-03T06:39:49Z DEBUG ipaobject 2020-06-03T06:39:49Z DEBUG ipasshuser 2020-06-03T06:39:49Z DEBUG ipaGroupObjectClasses: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG groupofnames 2020-06-03T06:39:49Z DEBUG nestedgroup 2020-06-03T06:39:49Z DEBUG ipausergroup 2020-06-03T06:39:49Z DEBUG ipaobject 2020-06-03T06:39:49Z DEBUG ipaPwdExpAdvNotify: 2020-06-03T06:39:49Z DEBUG 4 2020-06-03T06:39:49Z DEBUG ipaMaxHostnameLength: 2020-06-03T06:39:49Z DEBUG 64 2020-06-03T06:39:49Z DEBUG ipaMaxUsernameLength: 2020-06-03T06:39:49Z DEBUG 32 2020-06-03T06:39:49Z DEBUG ipaDefaultPrimaryGroup: 2020-06-03T06:39:49Z DEBUG ipausers 2020-06-03T06:39:49Z DEBUG ipaDefaultLoginShell: 2020-06-03T06:39:49Z DEBUG /bin/bash 2020-06-03T06:39:49Z DEBUG ipaHomesRootDir: 2020-06-03T06:39:49Z DEBUG /home 2020-06-03T06:39:49Z DEBUG ipaSearchRecordsLimit: 2020-06-03T06:39:49Z DEBUG 100 2020-06-03T06:39:49Z DEBUG ipaSearchTimeLimit: 2020-06-03T06:39:49Z DEBUG 2 2020-06-03T06:39:49Z DEBUG ipaGroupSearchFields: 2020-06-03T06:39:49Z DEBUG cn,description 2020-06-03T06:39:49Z DEBUG ipaUserSearchFields: 2020-06-03T06:39:49Z DEBUG uid,givenname,sn,telephonenumber,ou,title 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG ipaGuiConfig 2020-06-03T06:39:49Z DEBUG ipaConfigObject 2020-06-03T06:39:49Z DEBUG ipaUserAuthTypeClass 2020-06-03T06:39:49Z DEBUG ipaNameResolutionData 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipacertificatesubjectbase || ipaconfigstring || ipacustomfields || ipadefaultemaildomain || ipadefaultloginshell || ipadefaultprimarygroup || ipadomainresolutionorder || ipagroupobjectclasses || ipagroupsearchfields || ipahomesrootdir || ipakrbauthzdata || ipamaxhostnamelength || ipamaxusernamelength || ipamigrationenabled || ipapwdexpadvnotify || ipasearchrecordslimit || ipasearchtimelimit || ipaselinuxusermapdefault || ipaselinuxusermaporder || ipauserauthtype || ipauserobjectclasses || ipausersearchfields || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaguiconfig)")(version 3.0;acl "permission:System: Read Global Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/60-trusts.update 0.040 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/61-trusts-s4u2proxy.update' 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ipa-cifs-delegation-targets 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG groupOfPrincipals 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ipa-cifs-delegation-targets 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG groupOfPrincipals 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG ipaAllowedTarget: 2020-06-03T06:39:49Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG memberPrincipal: 2020-06-03T06:39:49Z DEBUG HTTP/master1.ipa.test@IPA.TEST 2020-06-03T06:39:49Z DEBUG HTTP/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ipa-http-delegation 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG ipaKrb5DelegationACL 2020-06-03T06:39:49Z DEBUG groupOfPrincipals 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG add: 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test' to ipaAllowedTarget, current value ['cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test', 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test', 'cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=ipa-http-delegation,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG ipaAllowedTarget: 2020-06-03T06:39:49Z DEBUG cn=ipa-ldap-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=ipa-cifs-delegation-targets,cn=s4u2proxy,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG memberPrincipal: 2020-06-03T06:39:49Z DEBUG HTTP/master1.ipa.test@IPA.TEST 2020-06-03T06:39:49Z DEBUG HTTP/replica1.ipa.test@IPA.TEST 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ipa-http-delegation 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG ipaKrb5DelegationACL 2020-06-03T06:39:49Z DEBUG groupOfPrincipals 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/61-trusts-s4u2proxy.update 0.004 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/62-ranges.update' 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=ranges,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=ranges,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ranges 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=ranges,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ranges 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=*,cn=ranges,cn=etc,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaIDrange)")(version 3.0;acl "CIFS service can manage ID ranges for trust"; allow(all) userdn="ldap:///krbprincipalname=cifs/*@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test" and groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || ipabaseid || ipabaserid || ipaidrangesize || ipanttrusteddomainsid || iparangetype || ipasecondarybaserid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaidrange)")(version 3.0;acl "permission:System: Read ID Ranges";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG New entry: cn=IPA Range-Check,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectclass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsSlapdPlugin 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG IPA Range-Check 2020-06-03T06:39:49Z DEBUG nsslapd-pluginpath: 2020-06-03T06:39:49Z DEBUG libipa_range_check 2020-06-03T06:39:49Z DEBUG nsslapd-plugininitfunc: 2020-06-03T06:39:49Z DEBUG ipa_range_check_init 2020-06-03T06:39:49Z DEBUG nsslapd-plugintype: 2020-06-03T06:39:49Z DEBUG preoperation 2020-06-03T06:39:49Z DEBUG nsslapd-pluginenabled: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginid: 2020-06-03T06:39:49Z DEBUG ipa_range_check_version 2020-06-03T06:39:49Z DEBUG nsslapd-pluginversion: 2020-06-03T06:39:49Z DEBUG 1.0 2020-06-03T06:39:49Z DEBUG nsslapd-pluginvendor: 2020-06-03T06:39:49Z DEBUG Red Hat, Inc. 2020-06-03T06:39:49Z DEBUG nsslapd-plugindescription: 2020-06-03T06:39:49Z DEBUG IPA Range-Check plugin 2020-06-03T06:39:49Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:49Z DEBUG database 2020-06-03T06:39:49Z DEBUG nsslapd-basedn: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=IPA Range-Check,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectclass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsSlapdPlugin 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG IPA Range-Check 2020-06-03T06:39:49Z DEBUG nsslapd-pluginpath: 2020-06-03T06:39:49Z DEBUG libipa_range_check 2020-06-03T06:39:49Z DEBUG nsslapd-plugininitfunc: 2020-06-03T06:39:49Z DEBUG ipa_range_check_init 2020-06-03T06:39:49Z DEBUG nsslapd-plugintype: 2020-06-03T06:39:49Z DEBUG preoperation 2020-06-03T06:39:49Z DEBUG nsslapd-pluginenabled: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginid: 2020-06-03T06:39:49Z DEBUG ipa_range_check_version 2020-06-03T06:39:49Z DEBUG nsslapd-pluginversion: 2020-06-03T06:39:49Z DEBUG 1.0 2020-06-03T06:39:49Z DEBUG nsslapd-pluginvendor: 2020-06-03T06:39:49Z DEBUG Red Hat, Inc. 2020-06-03T06:39:49Z DEBUG nsslapd-plugindescription: 2020-06-03T06:39:49Z DEBUG IPA Range-Check plugin 2020-06-03T06:39:49Z DEBUG nsslapd-plugin-depends-on-type: 2020-06-03T06:39:49Z DEBUG database 2020-06-03T06:39:49Z DEBUG nsslapd-basedn: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Posix IDs 2020-06-03T06:39:49Z DEBUG dnaExcludeScope: 2020-06-03T06:39:49Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG dnaFilter: 2020-06-03T06:39:49Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-03T06:39:49Z DEBUG dnaMagicRegen: 2020-06-03T06:39:49Z DEBUG -1 2020-06-03T06:39:49Z DEBUG dnaMaxValue: 2020-06-03T06:39:49Z DEBUG 1100 2020-06-03T06:39:49Z DEBUG dnaNextValue: 2020-06-03T06:39:49Z DEBUG 1101 2020-06-03T06:39:49Z DEBUG dnaScope: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG dnaSharedCfgDN: 2020-06-03T06:39:49Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG dnaThreshold: 2020-06-03T06:39:49Z DEBUG 500 2020-06-03T06:39:49Z DEBUG dnaType: 2020-06-03T06:39:49Z DEBUG uidNumber 2020-06-03T06:39:49Z DEBUG gidNumber 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG replace: (|(objectclass=posixAccount)(objectClass=posixGroup)) not found, skipping 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=Posix IDs,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Posix IDs 2020-06-03T06:39:49Z DEBUG dnaExcludeScope: 2020-06-03T06:39:49Z DEBUG cn=provisioning,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG dnaFilter: 2020-06-03T06:39:49Z DEBUG (|(objectClass=posixAccount)(objectClass=posixGroup)(objectClass=ipaIDobject)) 2020-06-03T06:39:49Z DEBUG dnaMagicRegen: 2020-06-03T06:39:49Z DEBUG -1 2020-06-03T06:39:49Z DEBUG dnaMaxValue: 2020-06-03T06:39:49Z DEBUG 1100 2020-06-03T06:39:49Z DEBUG dnaNextValue: 2020-06-03T06:39:49Z DEBUG 1101 2020-06-03T06:39:49Z DEBUG dnaScope: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG dnaSharedCfgDN: 2020-06-03T06:39:49Z DEBUG cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG dnaThreshold: 2020-06-03T06:39:49Z DEBUG 500 2020-06-03T06:39:49Z DEBUG dnaType: 2020-06-03T06:39:49Z DEBUG uidNumber 2020-06-03T06:39:49Z DEBUG gidNumber 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr=dnaNextRange || dnaNextValue || dnaMaxValue)(version 3.0;acl "permission:Modify DNA Range";allow (write) groupdn = "ldap:///cn=Modify DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr=cn || dnaMaxValue || dnaNextRange || dnaNextValue || dnaThreshold || dnaType || objectclass)(version 3.0;acl "permission:Read DNA Range";allow (read, search, compare) groupdn = "ldap:///cn=Read DNA Range,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/62-ranges.update 0.026 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews-sasl-mapping.update' 2020-06-03T06:39:49Z DEBUG New entry: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ID Overridden Principal 2020-06-03T06:39:49Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-03T06:39:49Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG nsSaslMapFilterTemplate: 2020-06-03T06:39:49Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2020-06-03T06:39:49Z DEBUG nsSaslMapPriority: 2020-06-03T06:39:49Z DEBUG 20 2020-06-03T06:39:49Z DEBUG nsSaslMapRegexString: 2020-06-03T06:39:49Z DEBUG \(.*\)@\(.*\) 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsSaslMapping 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=ID Overridden Principal,cn=mapping,cn=sasl,cn=config 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ID Overridden Principal 2020-06-03T06:39:49Z DEBUG nsSaslMapBaseDNTemplate: 2020-06-03T06:39:49Z DEBUG cn=default trust view,cn=views,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG nsSaslMapFilterTemplate: 2020-06-03T06:39:49Z DEBUG (&(ipaoriginaluid=\1@\2)(objectclass=ipaUserOverride)) 2020-06-03T06:39:49Z DEBUG nsSaslMapPriority: 2020-06-03T06:39:49Z DEBUG 20 2020-06-03T06:39:49Z DEBUG nsSaslMapRegexString: 2020-06-03T06:39:49Z DEBUG \(.*\)@\(.*\) 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsSaslMapping 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/71-idviews-sasl-mapping.update 0.014 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/71-idviews.update' 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=views,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=views,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG views 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || description || entryusn || gecos || gidnumber || homedirectory || ipaanchoruuid || ipaoriginaluid || ipasshpubkey || loginshell || modifytimestamp || objectclass || uid || uidnumber || usercertificate")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipadomainresolutionorder || modifytimestamp || objectclass")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Read ID Views";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=views,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG views 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || gidnumber || ipaanchoruuid || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipaGroupOverride)")(version 3.0;acl "permission:System: Read Group ID Overrides";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || description || entryusn || gecos || gidnumber || homedirectory || ipaanchoruuid || ipaoriginaluid || ipasshpubkey || loginshell || modifytimestamp || objectclass || uid || uidnumber || usercertificate")(targetfilter = "(objectclass=ipaUserOverride)")(version 3.0;acl "permission:System: Read User ID Overrides";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipadomainresolutionorder || modifytimestamp || objectclass")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Read ID Views";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/71-idviews.update 0.002 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/72-domainlevels.update' 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=Domain Level,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Domain Level 2020-06-03T06:39:49Z DEBUG ipaDomainLevel: 2020-06-03T06:39:49Z DEBUG 1 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG ipaDomainLevelConfig 2020-06-03T06:39:49Z DEBUG ipaConfigObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || ipadomainlevel || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipadomainlevelconfig)")(version 3.0;acl "permission:System: Read Domain Level";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=Domain Level,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Domain Level 2020-06-03T06:39:49Z DEBUG ipaDomainLevel: 2020-06-03T06:39:49Z DEBUG 1 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG ipaDomainLevelConfig 2020-06-03T06:39:49Z DEBUG ipaConfigObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || ipadomainlevel || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipadomainlevelconfig)")(version 3.0;acl "permission:System: Read Domain Level";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG ipaReplTopoManagedServer 2020-06-03T06:39:49Z DEBUG ipaConfigObject 2020-06-03T06:39:49Z DEBUG ipaSupportedDomainLevelConfig 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG replica1.ipa.test 2020-06-03T06:39:49Z DEBUG ipaReplTopoManagedSuffix: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG o=ipaca 2020-06-03T06:39:49Z DEBUG ipaMinDomainLevel: 2020-06-03T06:39:49Z DEBUG 1 2020-06-03T06:39:49Z DEBUG ipaMaxDomainLevel: 2020-06-03T06:39:49Z DEBUG 1 2020-06-03T06:39:49Z DEBUG add: 'ipaConfigObject' to objectClass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2020-06-03T06:39:49Z DEBUG add: updated value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaSupportedDomainLevelConfig', 'ipaConfigObject'] 2020-06-03T06:39:49Z DEBUG add: 'ipaSupportedDomainLevelConfig' to objectClass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaSupportedDomainLevelConfig', 'ipaConfigObject'] 2020-06-03T06:39:49Z DEBUG add: updated value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2020-06-03T06:39:49Z DEBUG only: set ipaMinDomainLevel to '1', current value ['1'] 2020-06-03T06:39:49Z DEBUG only: updated value ['1'] 2020-06-03T06:39:49Z DEBUG only: set ipaMaxDomainLevel to '1', current value ['1'] 2020-06-03T06:39:49Z DEBUG only: updated value ['1'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG ipaReplTopoManagedServer 2020-06-03T06:39:49Z DEBUG ipaConfigObject 2020-06-03T06:39:49Z DEBUG ipaSupportedDomainLevelConfig 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG replica1.ipa.test 2020-06-03T06:39:49Z DEBUG ipaReplTopoManagedSuffix: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG o=ipaca 2020-06-03T06:39:49Z DEBUG ipaMinDomainLevel: 2020-06-03T06:39:49Z DEBUG 1 2020-06-03T06:39:49Z DEBUG ipaMaxDomainLevel: 2020-06-03T06:39:49Z DEBUG 1 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/72-domainlevels.update 0.006 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/73-certmap.update' 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=certmap,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=certmap,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG ipaCertMapPromptUsername: 2020-06-03T06:39:49Z DEBUG FALSE 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG certmap 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG ipaCertMapConfigObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Modify Certmap Configuration";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Read Certmap Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=certmap,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG ipaCertMapPromptUsername: 2020-06-03T06:39:49Z DEBUG FALSE 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG certmap 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG ipaCertMapConfigObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Modify Certmap Configuration";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || ipacertmappromptusername")(targetfilter = "(objectclass=ipacertmapconfigobject)")(version 3.0;acl "permission:System: Read Certmap Configuration";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=certmaprules,cn=certmap,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=certmaprules,cn=certmap,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG certmaprules 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Add Certmap Rules";allow (add) groupdn = "ldap:///cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Delete Certmap Rules";allow (delete) groupdn = "ldap:///cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "associateddomain || cn || description || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Modify Certmap Rules";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "associateddomain || cn || createtimestamp || description || entryusn || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Read Certmap Rules";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=certmaprules,cn=certmap,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG certmaprules 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Add Certmap Rules";allow (add) groupdn = "ldap:///cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Delete Certmap Rules";allow (delete) groupdn = "ldap:///cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "associateddomain || cn || description || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Modify Certmap Rules";allow (write) groupdn = "ldap:///cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "associateddomain || cn || createtimestamp || description || entryusn || ipacertmapmaprule || ipacertmapmatchrule || ipacertmappriority || ipaenabledflag || modifytimestamp || objectclass")(targetfilter = "(objectclass=ipacertmaprule)")(version 3.0;acl "permission:System: Read Certmap Rules";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG memberOf: 2020-06-03T06:39:49Z DEBUG cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG description: 2020-06-03T06:39:49Z DEBUG Certificate Identity Mapping Administrators 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Certificate Identity Mapping Administrators 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG groupofnames 2020-06-03T06:39:49Z DEBUG nestedgroup 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=Certificate Identity Mapping Administrators,cn=privileges,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG memberOf: 2020-06-03T06:39:49Z DEBUG cn=System: Modify Certmap Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=System: Add Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=System: Delete Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=System: Modify Certmap Rules,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG description: 2020-06-03T06:39:49Z DEBUG Certificate Identity Mapping Administrators 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Certificate Identity Mapping Administrators 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG groupofnames 2020-06-03T06:39:49Z DEBUG nestedgroup 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG associatedDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG nisDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG info: 2020-06-03T06:39:49Z DEBUG IPA V2.0 2020-06-03T06:39:49Z DEBUG dc: 2020-06-03T06:39:49Z DEBUG ipa 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG domain 2020-06-03T06:39:49Z DEBUG pilotObject 2020-06-03T06:39:49Z DEBUG domainRelatedObject 2020-06-03T06:39:49Z DEBUG nisDomainObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG add: '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";)', '(targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";)', '(targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";)', '(targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";)', '(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";)', '(target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";)', '(targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";)', '(targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";)', '(targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";)', '(targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";)'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG associatedDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG nisDomain: 2020-06-03T06:39:49Z DEBUG ipa.test 2020-06-03T06:39:49Z DEBUG info: 2020-06-03T06:39:49Z DEBUG IPA V2.0 2020-06-03T06:39:49Z DEBUG dc: 2020-06-03T06:39:49Z DEBUG ipa 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG domain 2020-06-03T06:39:49Z DEBUG pilotObject 2020-06-03T06:39:49Z DEBUG domainRelatedObject 2020-06-03T06:39:49Z DEBUG nisDomainObject 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=retrieve certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Retrieve Certificates from the CA" ; allow (write) groupdn = "ldap:///cn=Retrieve Certificates from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificate" ; allow (write) groupdn = "ldap:///cn=Request Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate different host,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Request Certificates from a different host" ; allow (write) groupdn = "ldap:///cn=Request Certificates from a different host,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate status,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Get Certificates status from the CA" ; allow (write) groupdn = "ldap:///cn=Get Certificates status from the CA,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=revoke certificate,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Revoke Certificate"; allow (write) groupdn = "ldap:///cn=Revoke Certificate,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=certificate remove hold,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Certificate Remove Hold"; allow (write) groupdn = "ldap:///cn=Certificate Remove Hold,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "userpassword || krbprincipalkey || sambalmpassword || sambantpassword")(version 3.0; acl "selfservice:Self can write own password"; allow (write) userdn="ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "givenname || sn || cn || displayname || title || initials || loginshell || gecos || homephone || mobile || pager || facsimiletelephonenumber || telephonenumber || street || roomnumber || l || st || postalcode || manager || secretary || description || carlicense || labeleduri || inetuserhttpurl || seealso || employeetype || businesscategory || ou")(version 3.0;acl "selfservice:User Self service";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipasshpubkey")(version 3.0;acl "selfservice:Users can manage their own SSH public keys";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "usercertificate")(version 3.0;acl "selfservice:Users can manage their own X.509 certificates";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "objectclass || description || managedBy || ipatokenUniqueID || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial || ipatokenOwner")(version 3.0; acl "Users/managers can read basic token info"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipatokenTOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits || ipatokenTOTPtimeStep")(version 3.0; acl "Users/managers can see TOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipatokenHOTP)")(targetattrs = "ipatokenOTPalgorithm || ipatokenOTPdigits")(version 3.0; acl "Users/managers can see HOTP details"; allow (read, search, compare) userattr = "ipatokenOwner#USERDN" or userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(targetattrs = "description || ipatokenDisabled || ipatokenNotBefore || ipatokenNotAfter || ipatokenVendor || ipatokenModel || ipatokenSerial")(version 3.0; acl "Managers can write basic token info"; allow (write) userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Managers can delete tokens"; allow (delete) userattr = "managedBy#USERDN";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///ipatokenuniqueid=*,cn=otp,dc=ipa,dc=test")(targetfilter = "(objectClass=ipaToken)")(version 3.0; acl "Users can create self-managed tokens"; allow (add) userattr = "ipatokenOwner#SELFDN" and userattr = "managedBy#SELFDN";) 2020-06-03T06:39:49Z DEBUG (targetfilter="(objectclass=domain)")(targetattr="objectclass || dc || info || nisDomain || associatedDomain")(version 3.0; acl "Anonymous read access to DIT root"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr="parentid")(version 3.0; acl "Anonymous read access to parentID information"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr="altSecurityIdentities")(version 3.0; acl "Authenticated read access to altSecurityIdentities information"; allow(read, search, compare) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetfilter="(&(objectclass=nsContainer)(!(objectclass=krbPwdPolicy)))")(target!="ldap:///cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test")(targetattr="objectclass || cn")(version 3.0; acl "Anonymous read access to containers"; allow(read, search, compare) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr != "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || krbMKey || krbPrincipalName || krbCanonicalName || krbPwdHistory || krbLastPwdChange || krbExtraData || krbLastSuccessfulAuth || krbLastFailedAuth || ipaUniqueId || memberOf || enrolledBy || ipaNTHash || ipaProtectedOperation")(version 3.0; acl "Admin can manage any entry"; allow (all) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "userPassword || krbPrincipalKey || sambaLMPassword || sambaNTPassword || passwordHistory || ipaNTHash || krbPasswordExpiration")(version 3.0; acl "Admins can write passwords"; allow (add,delete,write) groupdn="ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectClass=krbPwdPolicy)")(targetattr = "krbMaxPwdLife || krbMinPwdLife || krbPwdMinDiffChars || krbPwdMinLength || krbPwdHistoryLength")(version 3.0;acl "Admins can write password policies"; allow (read, search, compare, write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="ipaUniqueId || memberOf || enrolledBy || krbExtraData || krbPrincipalName || krbCanonicalName || krbPasswordExpiration || krbLastPwdChange || krbLastSuccessfulAuth || krbLastFailedAuth")(version 3.0; acl "Admin read-only attributes"; allow (read, search, compare) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr="krbPrincipalName || krbCanonicalName")(version 3.0; acl "Admin can write principal names"; allow (write) groupdn = "ldap:///cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipausersearchfields || ipagroupsearchfields || ipasearchtimelimit || ipasearchrecordslimit || ipacustomfields || ipahomesrootdir || ipadefaultloginshell || ipadefaultprimarygroup || ipamaxusernamelength || ipapwdexpadvnotify || ipauserobjectclasses || ipagroupobjectclasses || ipadefaultemaildomain || ipamigrationenabled || ipacertificatesubjectbase || ipaconfigstring")(target = "ldap:///cn=ipaconfig,cn=etc,dc=ipa,dc=test" )(version 3.0 ; acl "permission:Write IPA Configuration"; allow (write) groupdn = "ldap:///cn=Write IPA Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "objectclass")(target = "ldap:///cn=request certificate ignore caacl,cn=virtual operations,cn=etc,dc=ipa,dc=test" )(version 3.0; acl "permission:Request Certificate ignoring CA ACLs"; allow (write) groupdn = "ldap:///cn=Request Certificate ignoring CA ACLs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaNTHash")(version 3.0; acl "Samba system principals can read and write NT passwords"; allow (read,write) groupdn="ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh || ipadnsversion || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Read DNS Configuration";allow (read) groupdn = "ldap:///cn=System: Read DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "idnsallowsyncptr || idnsforwarders || idnsforwardpolicy || idnspersistentsearch || idnszonerefresh")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsConfigObject)")(version 3.0;acl "permission:System: Write DNS Configuration";allow (write) groupdn = "ldap:///cn=System: Write DNS Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "idnsforwarders || idnsforwardpolicy || idnssoamname || idnssubstitutionvariable")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Modify DNS Servers Configuration";allow (write) groupdn = "ldap:///cn=System: Modify DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "createtimestamp || entryusn || idnsforwarders || idnsforwardpolicy || idnsserverid || idnssoamname || idnssubstitutionvariable || modifytimestamp || objectclass")(targetfilter = "(objectclass=idnsServerConfigObject)")(version 3.0;acl "permission:System: Read DNS Servers Configuration";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Servers Configuration,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Add DNS Entries";allow (add) groupdn = "ldap:///cn=System: Add DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaprivatekey || ipapublickey || ipasecretkey || ipasecretkeyref || ipawrappingkey || ipawrappingmech || ipk11allowedmechanisms || ipk11alwaysauthenticate || ipk11alwayssensitive || ipk11checkvalue || ipk11copyable || ipk11decrypt || ipk11derive || ipk11destroyable || ipk11distrusted || ipk11encrypt || ipk11enddate || ipk11extractable || ipk11id || ipk11keygenmechanism || ipk11keytype || ipk11label || ipk11local || ipk11modifiable || ipk11neverextractable || ipk11private || ipk11publickeyinfo || ipk11sensitive || ipk11sign || ipk11signrecover || ipk11startdate || ipk11subject || ipk11trusted || ipk11uniqueid || ipk11unwrap || ipk11unwraptemplate || ipk11verify || ipk11verifyrecover || ipk11wrap || ipk11wraptemplate || ipk11wrapwithtrusted || objectclass")(target = "ldap:///cn=keys,cn=sec,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Manage DNSSEC keys";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Manage DNSSEC metadata";allow (all) groupdn = "ldap:///cn=System: Manage DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || createtimestamp || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || entryusn || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || modifytimestamp || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read DNS Entries";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || idnssecalgorithm || idnsseckeyactivate || idnsseckeycreated || idnsseckeydelete || idnsseckeyinactive || idnsseckeypublish || idnsseckeyref || idnsseckeyrevoke || idnsseckeysep || idnsseckeyzone || modifytimestamp || objectclass")(target = "ldap:///cn=dns,dc=ipa,dc=test")(targetfilter = "(objectclass=idnsSecKey)")(version 3.0;acl "permission:System: Read DNSSEC metadata";allow (compare,read,search) groupdn = "ldap:///cn=System: Read DNSSEC metadata,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Remove DNS Entries";allow (delete) groupdn = "ldap:///cn=System: Remove DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "a6record || aaaarecord || afsdbrecord || aplrecord || arecord || certrecord || cn || cnamerecord || dhcidrecord || dlvrecord || dnamerecord || dnsclass || dnsdefaultttl || dnsttl || dsrecord || hinforecord || hiprecord || idnsallowdynupdate || idnsallowquery || idnsallowsyncptr || idnsallowtransfer || idnsforwarders || idnsforwardpolicy || idnsname || idnssecinlinesigning || idnssoaexpire || idnssoaminimum || idnssoamname || idnssoarefresh || idnssoaretry || idnssoarname || idnssoaserial || idnstemplateattribute || idnsupdatepolicy || idnszoneactive || ipseckeyrecord || keyrecord || kxrecord || locrecord || managedby || mdrecord || minforecord || mxrecord || naptrrecord || nsec3paramrecord || nsecrecord || nsrecord || nxtrecord || objectclass || ptrrecord || rprecord || rrsigrecord || sigrecord || spfrecord || srvrecord || sshfprecord || tlsarecord || txtrecord || unknownrecord || urirecord")(target = "ldap:///idnsname=*,cn=dns,dc=ipa,dc=test")(version 3.0;acl "permission:System: Update DNS Entries";allow (write) groupdn = "ldap:///cn=System: Update DNS Entries,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gidnumber || memberuid || modifytimestamp || objectclass")(target = "ldap:///cn=groups,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Group Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || macaddress || modifytimestamp || objectclass")(target = "ldap:///cn=computers,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Host Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || membernisnetgroup || modifytimestamp || nisnetgrouptriple || objectclass")(target = "ldap:///cn=ng,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Netgroup Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "aci")(version 3.0;acl "permission:System: Read ACIs";allow (compare,read,search) groupdn = "ldap:///cn=System: Read ACIs,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || ou || sudocommand || sudohost || sudonotafter || sudonotbefore || sudooption || sudoorder || sudorunas || sudorunasgroup || sudorunasuser || sudouser")(target = "ldap:///ou=sudoers,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read Sudoers compat tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || entryusn || gecos || gidnumber || homedirectory || loginshell || modifytimestamp || objectclass || uid || uidnumber")(target = "ldap:///cn=users,cn=*,cn=views,cn=compat,dc=ipa,dc=test")(version 3.0;acl "permission:System: Read User Views Compat Tree";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Add Vaults";allow (add) groupdn = "ldap:///cn=System: Add Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Delete Vaults";allow (delete) groupdn = "ldap:///cn=System: Delete Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "member")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Membership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Membership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Manage Vault Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || description || ipavaultpublickey || ipavaultsalt || ipavaulttype || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Modify Vaults";allow (write) groupdn = "ldap:///cn=System: Modify Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || ipavaultpublickey || ipavaultsalt || ipavaulttype || member || memberhost || memberuser || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVault)")(version 3.0;acl "permission:System: Read Vaults";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vaults,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Add Vault Containers";allow (add) groupdn = "ldap:///cn=System: Add Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Delete Vault Containers";allow (delete) groupdn = "ldap:///cn=System: Delete Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Manage Vault Container Ownership";allow (write) groupdn = "ldap:///cn=System: Manage Vault Container Ownership,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || description || objectclass")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Modify Vault Containers";allow (write) groupdn = "ldap:///cn=System: Modify Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || entryusn || modifytimestamp || objectclass || owner")(target = "ldap:///cn=vaults,cn=kra,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaVaultContainer)")(version 3.0;acl "permission:System: Read Vault Containers";allow (compare,read,search) groupdn = "ldap:///cn=System: Read Vault Containers,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipaanchoruuid")(target = "ldap:///cn=*,cn=compat,dc=ipa,dc=test")(targetfilter = "(objectclass=ipaOverrideTarget)")(version 3.0;acl "permission:System: Compat Tree ID View targets";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipacertmapdata")(targattrfilters="add=objectclass:(objectclass=ipacertmapobject)")(version 3.0;acl "selfservice:Users can manage their own X.509 certificate identity mappings";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-certmap.update 0.017 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/73-custodia.update' 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG custodia 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG custodia 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG dogtag 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=dogtag,cn=custodia,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG dogtag 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-custodia.update 0.004 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/73-winsync.update' 2020-06-03T06:39:49Z DEBUG New entry: uid=passsync,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG addifexist: 'inetUser' to objectClass, current value [] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: uid=passsync,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/73-winsync.update 0.001 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/75-user-trust-attributes.update' 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbauthindmaxrenewableage || krbauthindmaxticketlife || krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG add: '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)' to aci, current value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)', '(targetattr = "krbauthindmaxrenewableage || krbauthindmaxticketlife || krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "usercertificate")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)', '(targetattr = "krbauthindmaxrenewableage || krbauthindmaxticketlife || krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "usercertificate")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)' to aci, current value ['(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)', '(targetattr = "krbauthindmaxrenewableage || krbauthindmaxticketlife || krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "usercertificate")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)'] 2020-06-03T06:39:49Z DEBUG add: updated value ['(targetattr = "krbauthindmaxrenewableage || krbauthindmaxticketlife || krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "usercertificate")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipasshpubkey")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";)', '(targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";)', '(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";)', '(targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";)'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=accounts,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsContainer 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr = "krbauthindmaxrenewableage || krbauthindmaxticketlife || krbmaxrenewableage || krbmaxticketlife")(targetfilter = "(objectclass=krbticketpolicyaux)")(version 3.0;acl "permission:System: Read User Kerberos Ticket Policy";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Ticket Policy,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "uid")(target = "ldap:///uid=*,cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify User RDN";allow (write) groupdn = "ldap:///cn=System: Modify User RDN,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Add Users";allow (add) groupdn = "ldap:///cn=System: Add Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbpasswordexpiration || krbprincipalkey || passwordhistory || sambalmpassword || sambantpassword || userpassword")(targetfilter = "(&(!(memberOf=cn=admins,cn=groups,cn=accounts,dc=ipa,dc=test))(objectclass=posixaccount))")(version 3.0;acl "permission:System: Change User password";allow (write) groupdn = "ldap:///cn=System: Change User password,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipacertmapdata || objectclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificate Mappings";allow (write) groupdn = "ldap:///cn=System: Manage User Certificate Mappings,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "usercertificate")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Certificates";allow (write) groupdn = "ldap:///cn=System: Manage User Certificates,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbcanonicalname || krbprincipalname")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User Principals";allow (write) groupdn = "ldap:///cn=System: Manage User Principals,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipasshpubkey")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Manage User SSH Public Keys";allow (write) groupdn = "ldap:///cn=System: Manage User SSH Public Keys,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "businesscategory || carlicense || cn || departmentnumber || description || displayname || employeenumber || employeetype || facsimiletelephonenumber || gecos || givenname || homedirectory || homephone || inetuserhttpurl || initials || l || labeleduri || loginshell || mail || manager || mepmanagedentry || mobile || objectclass || ou || pager || postalcode || preferredlanguage || roomnumber || secretary || seealso || sn || st || street || telephonenumber || title || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Modify Users";allow (write) groupdn = "ldap:///cn=System: Modify Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "audio || businesscategory || carlicense || departmentnumber || destinationindicator || employeenumber || employeetype || facsimiletelephonenumber || homephone || homepostaladdress || inetuserhttpurl || inetuserstatus || internationalisdnnumber || ipacertmapdata || jpegphoto || l || labeleduri || mail || mobile || o || ou || pager || photo || physicaldeliveryofficename || postaladdress || postalcode || postofficebox || preferreddeliverymethod || preferredlanguage || registeredaddress || roomnumber || secretary || seealso || st || street || telephonenumber || teletexterminalidentifier || telexnumber || usercertificate || usersmimecertificate || x121address || x500uniqueidentifier")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Addressbook Attributes";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipasshpubkey || ipauniqueid || ipauserauthtype || userclass")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User IPA Attributes";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krbcanonicalname || krblastpwdchange || krbpasswordexpiration || krbprincipalaliases || krbprincipalexpiration || krbprincipalname || krbprincipaltype || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Attributes";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krblastadminunlock || krblastfailedauth || krblastpwdchange || krblastsuccessfulauth || krbloginfailedcount || krbpwdpolicyreference || krbticketpolicyreference || krbupenabled")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Kerberos Login Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User Kerberos Login Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "memberof")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Membership";allow (compare,read,search) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ntuniqueid || ntuseracctexpires || ntusercodepage || ntuserdeleteaccount || ntuserdomainid || ntuserlastlogoff || ntuserlastlogon")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User NT Attributes";allow (compare,read,search) groupdn = "ldap:///cn=System: Read User NT Attributes,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "cn || createtimestamp || description || displayname || entryusn || gecos || gidnumber || givenname || homedirectory || initials || ipantsecurityidentifier || loginshell || manager || modifytimestamp || objectclass || sn || title || uid || uidnumber")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Read User Standard Attributes";allow (compare,read,search) userdn = "ldap:///anyone";) 2020-06-03T06:39:49Z DEBUG (targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Remove Users";allow (delete) groupdn = "ldap:///cn=System: Remove Users,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "krblastadminunlock || krbloginfailedcount || nsaccountlock")(targetfilter = "(objectclass=posixaccount)")(version 3.0;acl "permission:System: Unlock User";allow (write) groupdn = "ldap:///cn=System: Unlock User,cn=permissions,cn=pbac,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "system:Allow trust agents to read user SMB attributes";allow (read) groupdn = "ldap:///cn=adtrust agents,cn=sysaccounts,cn=etc,dc=ipa,dc=test";) 2020-06-03T06:39:49Z DEBUG (targetattr = "ipantlogonscript || ipantprofilepath || ipanthomedirectory || ipanthomedirectorydrive")(version 3.0;acl "selfservice:Users can manage their SMB attributes";allow (write) userdn = "ldap:///self";) 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/75-user-trust-attributes.update 0.004 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/80-schema_compat.update' 2020-06-03T06:39:49Z DEBUG New entry: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectclass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsSlapdPlugin 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Schema Compatibility 2020-06-03T06:39:49Z DEBUG nsslapd-pluginpath: 2020-06-03T06:39:49Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2020-06-03T06:39:49Z DEBUG nsslapd-plugininitfunc: 2020-06-03T06:39:49Z DEBUG schema_compat_plugin_init 2020-06-03T06:39:49Z DEBUG nsslapd-plugintype: 2020-06-03T06:39:49Z DEBUG object 2020-06-03T06:39:49Z DEBUG nsslapd-pluginenabled: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginid: 2020-06-03T06:39:49Z DEBUG schema-compat-plugin 2020-06-03T06:39:49Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:49Z DEBUG 40 2020-06-03T06:39:49Z DEBUG nsslapd-pluginversion: 2020-06-03T06:39:49Z DEBUG 0.8 2020-06-03T06:39:49Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginvendor: 2020-06-03T06:39:49Z DEBUG redhat.com 2020-06-03T06:39:49Z DEBUG nsslapd-plugindescription: 2020-06-03T06:39:49Z DEBUG Schema Compatibility Plugin 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectclass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsSlapdPlugin 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Schema Compatibility 2020-06-03T06:39:49Z DEBUG nsslapd-pluginpath: 2020-06-03T06:39:49Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2020-06-03T06:39:49Z DEBUG nsslapd-plugininitfunc: 2020-06-03T06:39:49Z DEBUG schema_compat_plugin_init 2020-06-03T06:39:49Z DEBUG nsslapd-plugintype: 2020-06-03T06:39:49Z DEBUG object 2020-06-03T06:39:49Z DEBUG nsslapd-pluginenabled: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginid: 2020-06-03T06:39:49Z DEBUG schema-compat-plugin 2020-06-03T06:39:49Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:49Z DEBUG 40 2020-06-03T06:39:49Z DEBUG nsslapd-pluginversion: 2020-06-03T06:39:49Z DEBUG 0.8 2020-06-03T06:39:49Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginvendor: 2020-06-03T06:39:49Z DEBUG redhat.com 2020-06-03T06:39:49Z DEBUG nsslapd-plugindescription: 2020-06-03T06:39:49Z DEBUG Schema Compatibility Plugin 2020-06-03T06:39:49Z DEBUG New entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=users 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=users, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG uid=%{uid} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG gecos=%{cn} 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG uidNumber=%{uidNumber} 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG loginShell=%{loginShell} 2020-06-03T06:39:49Z DEBUG homeDirectory=%{homeDirectory} 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=users 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=users, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG uid=%{uid} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG gecos=%{cn} 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG uidNumber=%{uidNumber} 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG loginShell=%{loginShell} 2020-06-03T06:39:49Z DEBUG homeDirectory=%{homeDirectory} 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG New entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG groups 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=groups 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=groups, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG memberUid=%{memberUid} 2020-06-03T06:39:49Z DEBUG memberUid=%deref_r("member","uid") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG groups 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=groups 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=groups, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG memberUid=%{memberUid} 2020-06-03T06:39:49Z DEBUG memberUid=%deref_r("member","uid") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG New entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG add: 'top' to objectClass, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['top'] 2020-06-03T06:39:49Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2020-06-03T06:39:49Z DEBUG add: updated value ['top', 'extensibleObject'] 2020-06-03T06:39:49Z DEBUG add: 'ng' to cn, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['ng'] 2020-06-03T06:39:49Z DEBUG add: 'cn=compat, dc=ipa,dc=test' to schema-compat-container-group, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=compat, dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=ng' to schema-compat-container-rdn, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=ng'] 2020-06-03T06:39:49Z DEBUG add: 'yes' to schema-compat-check-access, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['yes'] 2020-06-03T06:39:49Z DEBUG add: 'cn=ng, cn=alt, dc=ipa,dc=test' to schema-compat-search-base, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=ng, cn=alt, dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: '(objectclass=ipaNisNetgroup)' to schema-compat-search-filter, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['(objectclass=ipaNisNetgroup)'] 2020-06-03T06:39:49Z DEBUG add: 'cn=%{cn}' to schema-compat-entry-rdn, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=%{cn}'] 2020-06-03T06:39:49Z DEBUG add: 'objectclass=nisNetgroup' to schema-compat-entry-attribute, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=nisNetgroup'] 2020-06-03T06:39:49Z DEBUG add: 'memberNisNetgroup=%deref_r("member","cn")' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")'] 2020-06-03T06:39:49Z DEBUG add: 'nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-})' to schema-compat-entry-attribute, current value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ng 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=ng 2020-06-03T06:39:49Z DEBUG schema-compat-check-access: 2020-06-03T06:39:49Z DEBUG yes 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=ng, cn=alt, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (objectclass=ipaNisNetgroup) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=nisNetgroup 2020-06-03T06:39:49Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2020-06-03T06:39:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2020-06-03T06:39:49Z DEBUG New entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG add: 'top' to objectClass, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['top'] 2020-06-03T06:39:49Z DEBUG add: 'extensibleObject' to objectClass, current value ['top'] 2020-06-03T06:39:49Z DEBUG add: updated value ['top', 'extensibleObject'] 2020-06-03T06:39:49Z DEBUG add: 'sudoers' to cn, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['sudoers'] 2020-06-03T06:39:49Z DEBUG add: 'ou=SUDOers, dc=ipa,dc=test' to schema-compat-container-group, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['ou=SUDOers, dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=sudorules, cn=sudo, dc=ipa,dc=test' to schema-compat-search-base, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=sudorules, cn=sudo, dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: '(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))' to schema-compat-search-filter, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['(&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE)))'] 2020-06-03T06:39:49Z DEBUG add: '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")' to schema-compat-entry-rdn, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2020-06-03T06:39:49Z DEBUG add: 'objectclass=sudoRole' to schema-compat-entry-attribute, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole'] 2020-06-03T06:39:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoOption=%{ipaSudoOpt}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG sudoers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG ou=SUDOers, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=sudorules, cn=sudo, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=sudoRole 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-03T06:39:49Z DEBUG New entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG computers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=computers 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=computers, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%first("%{fqdn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=device 2020-06-03T06:39:49Z DEBUG objectclass=ieee802Device 2020-06-03T06:39:49Z DEBUG cn=%{fqdn} 2020-06-03T06:39:49Z DEBUG macAddress=%{macAddress} 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG computers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=computers 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=computers, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%first("%{fqdn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=device 2020-06-03T06:39:49Z DEBUG objectclass=ieee802Device 2020-06-03T06:39:49Z DEBUG cn=%{fqdn} 2020-06-03T06:39:49Z DEBUG macAddress=%{macAddress} 2020-06-03T06:39:49Z DEBUG Updating existing entry: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG VLV Request Control 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG directoryServerFeature 2020-06-03T06:39:49Z DEBUG oid: 2020-06-03T06:39:49Z DEBUG 2.16.840.1.113730.3.4.9 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";) 2020-06-03T06:39:49Z DEBUG only: set aci to '(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )', current value ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)'] 2020-06-03T06:39:49Z DEBUG only: updated value ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: oid=2.16.840.1.113730.3.4.9,cn=features,cn=config 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG VLV Request Control 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG directoryServerFeature 2020-06-03T06:39:49Z DEBUG oid: 2020-06-03T06:39:49Z DEBUG 2.16.840.1.113730.3.4.9 2020-06-03T06:39:49Z DEBUG aci: 2020-06-03T06:39:49Z DEBUG (targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; ) 2020-06-03T06:39:49Z DEBUG [(1, 'aci', ['(targetattr != "aci")(version 3.0; acl "VLV Request Control"; allow( read, search, compare, proxy ) userdn = "ldap:///all";)']), (0, 'aci', ['(targetattr !="aci")(version 3.0; acl "VLV Request Control"; allow (read, search, compare, proxy) userdn = "ldap:///anyone"; )'])] 2020-06-03T06:39:49Z DEBUG Updated 1 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG sudoers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG ou=SUDOers, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=sudorules, cn=sudo, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=sudoRole 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-03T06:39:49Z DEBUG only: set schema-compat-entry-rdn to '%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")', current value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2020-06-03T06:39:49Z DEBUG only: updated value ['%ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsGroup=%deref("ipaSudoRunAs","cn")' not in schema-compat-entry-attribute 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsUser=%{ipaSudoRunAsExtUser}' not in schema-compat-entry-attribute 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoRunAsUser=%%%{ipaSudoRunAsExtUserGroup}'] 2020-06-03T06:39:49Z DEBUG remove: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsUser=%deref("ipaSudoRunAs","uid")' not in schema-compat-entry-attribute 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsGroup=%{ipaSudoRunAsExtGroup}' not in schema-compat-entry-attribute 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' from schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")'] 2020-06-03T06:39:49Z DEBUG remove: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' not in schema-compat-entry-attribute 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG sudoers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG ou=SUDOers, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=sudorules, cn=sudo, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=sudoRole 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG sudoers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG ou=SUDOers, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=sudorules, cn=sudo, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=sudoRole 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2020-06-03T06:39:49Z DEBUG add: 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")")' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")'] 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG add: 'dc=ipa,dc=test' to schema-compat-restrict-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-03T06:39:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG sudoers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG ou=SUDOers, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=sudorules, cn=sudo, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=sudoRole 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test']), (0, 'schema-compat-entry-attribute', ['sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")']), (2, 'schema-compat-restrict-subtree', ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-03T06:39:49Z DEBUG Updated 1 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ng 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=ng 2020-06-03T06:39:49Z DEBUG schema-compat-check-access: 2020-06-03T06:39:49Z DEBUG yes 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=ng, cn=alt, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (objectclass=ipaNisNetgroup) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=nisNetgroup 2020-06-03T06:39:49Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2020-06-03T06:39:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","-",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","-"),%{nisDomainName:-}) 2020-06-03T06:39:49Z DEBUG replace: updated value ['objectclass=nisNetgroup', 'memberNisNetgroup=%deref_r("member","cn")', 'nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})'] 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG add: 'dc=ipa,dc=test' to schema-compat-restrict-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-03T06:39:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=ng,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG ng 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=ng 2020-06-03T06:39:49Z DEBUG schema-compat-check-access: 2020-06-03T06:39:49Z DEBUG yes 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=ng, cn=alt, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (objectclass=ipaNisNetgroup) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=nisNetgroup 2020-06-03T06:39:49Z DEBUG memberNisNetgroup=%deref_r("member","cn") 2020-06-03T06:39:49Z DEBUG nisNetgroupTriple=(%link("%ifeq(\"hostCategory\",\"all\",\"\",\"%collect(\\\"%{externalHost}\\\",\\\"%deref(\\\\\\\"memberHost\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberHost\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"fqdn\\\\\\\")\\\")\")","%ifeq(\"hostCategory\",\"all\",\"\",\"-\")",",","%ifeq(\"userCategory\",\"all\",\"\",\"%collect(\\\"%deref(\\\\\\\"memberUser\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\",\\\"%deref_r(\\\\\\\"memberUser\\\\\\\",\\\\\\\"member\\\\\\\",\\\\\\\"uid\\\\\\\")\\\")\")","%ifeq(\"userCategory\",\"all\",\"\",\"-\")"),%{nisDomainName:-}) 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test']), (1, 'schema-compat-entry-attribute', ['nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","-",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","-"),%{nisDomainName:-})']), (0, 'schema-compat-entry-attribute', ['nisNetgroupTriple=(%link("%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%{externalHost}\\\\\\",\\\\\\"%deref(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberHost\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"fqdn\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"hostCategory\\",\\"all\\",\\"\\",\\"-\\")",",","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"%collect(\\\\\\"%deref(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\",\\\\\\"%deref_r(\\\\\\\\\\\\\\"memberUser\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"member\\\\\\\\\\\\\\",\\\\\\\\\\\\\\"uid\\\\\\\\\\\\\\")\\\\\\")\\")","%ifeq(\\"userCategory\\",\\"all\\",\\"\\",\\"-\\")"),%{nisDomainName:-})']), (2, 'schema-compat-restrict-subtree', ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-03T06:39:49Z DEBUG Updated 1 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG computers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=computers 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=computers, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%first("%{fqdn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=device 2020-06-03T06:39:49Z DEBUG objectclass=ieee802Device 2020-06-03T06:39:49Z DEBUG cn=%{fqdn} 2020-06-03T06:39:49Z DEBUG macAddress=%{macAddress} 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG add: 'dc=ipa,dc=test' to schema-compat-restrict-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-03T06:39:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=computers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG computers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=computers 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=computers, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(macAddress=*)(fqdn=*)(objectClass=ipaHost)) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%first("%{fqdn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=device 2020-06-03T06:39:49Z DEBUG objectclass=ieee802Device 2020-06-03T06:39:49Z DEBUG cn=%{fqdn} 2020-06-03T06:39:49Z DEBUG macAddress=%{macAddress} 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test']), (2, 'schema-compat-restrict-subtree', ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-03T06:39:49Z DEBUG Updated 1 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG sudoers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG ou=SUDOers, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=sudorules, cn=sudo, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=sudoRole 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG add: 'sudoOrder=%{sudoOrder}' to schema-compat-entry-attribute, current value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=sudoRole', 'sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\\"memberUser\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\\"memberUser\\",\\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\\",\\"member\\",\\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\\",\\"uid\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\\"memberUser\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\\"memberUser\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\\"memberHost\\",\\"(objectclass=ipaHost)\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\\",\\"member\\",\\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\\",\\"fqdn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\\"memberHost\\",\\"(objectclass=ipaNisNetgroup)\\",\\"cn\\")")', 'sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\\"memberAllowCmd\\",\\"sudoCmd\\")")', 'sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\\"memberAllowCmd\\",\\"member\\",\\"sudoCmd\\")")', 'sudoCommand=!%deref("memberDenyCmd","sudoCmd")', 'sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixAccount)\\",\\"uid\\")")', 'sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\\"ipaSudoRunAs\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}")', 'sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\\"ipaSudoRunAsGroup\\",\\"(objectclass=posixGroup)\\",\\"cn\\")")', 'sudoOption=%{ipaSudoOpt}', 'sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn")', 'sudoOrder=%{sudoOrder}'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=sudoers,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG sudoers 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG ou=SUDOers, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=sudorules, cn=sudo, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG (&(objectclass=ipaSudoRule)(!(compatVisible=FALSE))(!(ipaEnabledFlag=FALSE))) 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG %ifeq("ipaEnabledFlag", "FALSE", "DISABLED", "cn=%{cn}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=sudoRole 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%{externalUser}") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_f(\"memberUser\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%deref_rf(\"memberUser\",\"(&(objectclass=ipaUserGroup)(!(objectclass=posixGroup)))\",\"member\",\"(|(objectclass=ipaUserGroup)(objectclass=posixAccount))\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","%%%deref_f(\"memberUser\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoUser=%ifeq("userCategory","all","ALL","+%deref_f(\"memberUser\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{externalHost}") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_f(\"memberHost\",\"(objectclass=ipaHost)\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%deref_rf(\"memberHost\",\"(&(objectclass=ipaHostGroup)(!(objectclass=mepOriginEntry)))\",\"member\",\"(|(objectclass=ipaHostGroup)(objectclass=ipaHost))\",\"fqdn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(&(objectclass=ipaHostGroup)(objectclass=mepOriginEntry))\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","+%deref_f(\"memberHost\",\"(objectclass=ipaNisNetgroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoHost=%ifeq("hostCategory","all","ALL","%{hostMask}") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref(\"memberAllowCmd\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=%ifeq("cmdCategory","all","ALL","%deref_r(\"memberAllowCmd\",\"member\",\"sudoCmd\")") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref("memberDenyCmd","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoCommand=!%deref_r("memberDenyCmd","member","sudoCmd") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%{ipaSudoRunAsExtUser}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%{ipaSudoRunAsExtUserGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixAccount)\",\"uid\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsUser=%ifeq("ipaSudoRunAsUserCategory","all","ALL","%%%deref_f(\"ipaSudoRunAs\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%{ipaSudoRunAsExtGroup}") 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%ifeq("ipaSudoRunAsGroupCategory","all","ALL","%deref_f(\"ipaSudoRunAsGroup\",\"(objectclass=posixGroup)\",\"cn\")") 2020-06-03T06:39:49Z DEBUG sudoOption=%{ipaSudoOpt} 2020-06-03T06:39:49Z DEBUG sudoRunAsGroup=%deref_f("ipaSudoRunAsGroup","(objectclass=posixGroup)","cn") 2020-06-03T06:39:49Z DEBUG sudoOrder=%{sudoOrder} 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG [(0, 'schema-compat-entry-attribute', ['sudoOrder=%{sudoOrder}'])] 2020-06-03T06:39:49Z DEBUG Updated 1 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=users 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=users, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG uid=%{uid} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG gecos=%{cn} 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG uidNumber=%{uidNumber} 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG loginShell=%{loginShell} 2020-06-03T06:39:49Z DEBUG homeDirectory=%{homeDirectory} 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG add: 'dc=ipa,dc=test' to schema-compat-restrict-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-03T06:39:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=users 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=users, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG uid=%{uid} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG gecos=%{cn} 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG uidNumber=%{uidNumber} 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG loginShell=%{loginShell} 2020-06-03T06:39:49Z DEBUG homeDirectory=%{homeDirectory} 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test']), (2, 'schema-compat-restrict-subtree', ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-03T06:39:49Z DEBUG Updated 1 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG groups 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=groups 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=groups, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG memberUid=%{memberUid} 2020-06-03T06:39:49Z DEBUG memberUid=%deref_r("member","uid") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'cn=changelog' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' from schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG remove: 'o=ipaca' not in schema-compat-ignore-subtree 2020-06-03T06:39:49Z DEBUG add: 'dc=ipa,dc=test' to schema-compat-restrict-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=Schema Compatibility,cn=plugins,cn=config' to schema-compat-restrict-subtree, current value ['dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'] 2020-06-03T06:39:49Z DEBUG add: 'cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value [] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test' to schema-compat-ignore-subtree, current value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG add: updated value ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG groups 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=groups 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=groups, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG memberUid=%{memberUid} 2020-06-03T06:39:49Z DEBUG memberUid=%deref_r("member","uid") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG [(2, 'schema-compat-ignore-subtree', ['cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test', 'cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test']), (2, 'schema-compat-restrict-subtree', ['dc=ipa,dc=test', 'cn=Schema Compatibility,cn=plugins,cn=config'])] 2020-06-03T06:39:49Z DEBUG Updated 1 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsSlapdPlugin 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Schema Compatibility 2020-06-03T06:39:49Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:49Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2020-06-03T06:39:49Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:49Z DEBUG schema_compat_plugin_init 2020-06-03T06:39:49Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:49Z DEBUG object 2020-06-03T06:39:49Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:49Z DEBUG schema-compat-plugin 2020-06-03T06:39:49Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:49Z DEBUG 40 2020-06-03T06:39:49Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:49Z DEBUG 0.8 2020-06-03T06:39:49Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:49Z DEBUG redhat.com 2020-06-03T06:39:49Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:49Z DEBUG Schema Compatibility Plugin 2020-06-03T06:39:49Z DEBUG add: '40' to nsslapd-pluginprecedence, current value ['40'] 2020-06-03T06:39:49Z DEBUG add: updated value ['40'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG nsSlapdPlugin 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG Schema Compatibility 2020-06-03T06:39:49Z DEBUG nsslapd-pluginPath: 2020-06-03T06:39:49Z DEBUG /usr/lib64/dirsrv/plugins/schemacompat-plugin.so 2020-06-03T06:39:49Z DEBUG nsslapd-pluginInitfunc: 2020-06-03T06:39:49Z DEBUG schema_compat_plugin_init 2020-06-03T06:39:49Z DEBUG nsslapd-pluginType: 2020-06-03T06:39:49Z DEBUG object 2020-06-03T06:39:49Z DEBUG nsslapd-pluginEnabled: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginId: 2020-06-03T06:39:49Z DEBUG schema-compat-plugin 2020-06-03T06:39:49Z DEBUG nsslapd-pluginprecedence: 2020-06-03T06:39:49Z DEBUG 40 2020-06-03T06:39:49Z DEBUG nsslapd-pluginVersion: 2020-06-03T06:39:49Z DEBUG 0.8 2020-06-03T06:39:49Z DEBUG nsslapd-pluginbetxn: 2020-06-03T06:39:49Z DEBUG on 2020-06-03T06:39:49Z DEBUG nsslapd-pluginVendor: 2020-06-03T06:39:49Z DEBUG redhat.com 2020-06-03T06:39:49Z DEBUG nsslapd-pluginDescription: 2020-06-03T06:39:49Z DEBUG Schema Compatibility Plugin 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=users 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=users, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG uid=%{uid} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG gecos=%{cn} 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG uidNumber=%{uidNumber} 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG loginShell=%{loginShell} 2020-06-03T06:39:49Z DEBUG homeDirectory=%{homeDirectory} 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")'] 2020-06-03T06:39:49Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2020-06-03T06:39:49Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=users 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=users, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG uid=%{uid} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG gecos=%{cn} 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG uidNumber=%{uidNumber} 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG loginShell=%{loginShell} 2020-06-03T06:39:49Z DEBUG homeDirectory=%{homeDirectory} 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG groups 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=groups 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=groups, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG memberUid=%{memberUid} 2020-06-03T06:39:49Z DEBUG memberUid=%deref_r("member","uid") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG add: '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")'] 2020-06-03T06:39:49Z DEBUG add: 'ipaanchoruuid=%{ipaanchoruuid}' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2020-06-03T06:39:49Z DEBUG add: '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG groups 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=groups 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=groups, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG memberUid=%{memberUid} 2020-06-03T06:39:49Z DEBUG memberUid=%deref_r("member","uid") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG [] 2020-06-03T06:39:49Z DEBUG Updated 0 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=users 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=users, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG uid=%{uid} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG gecos=%{cn} 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG uidNumber=%{uidNumber} 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG loginShell=%{loginShell} 2020-06-03T06:39:49Z DEBUG homeDirectory=%{homeDirectory} 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG add: 'uid=%{uid}' to schema-compat-entry-attribute, current value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG add: updated value ['objectclass=posixAccount', 'gecos=%{cn}', 'cn=%{cn}', 'uidNumber=%{uidNumber}', 'gidNumber=%{gidNumber}', 'loginShell=%{loginShell}', 'homeDirectory=%{homeDirectory}', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'uid=%{uid}'] 2020-06-03T06:39:49Z DEBUG replace: updated value ['uid=%first("%{uid}")'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=users,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG users 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=users 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=users, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG uid=%first("%{uid}") 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixAccount 2020-06-03T06:39:49Z DEBUG gecos=%{cn} 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG uidNumber=%{uidNumber} 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG loginShell=%{loginShell} 2020-06-03T06:39:49Z DEBUG homeDirectory=%{homeDirectory} 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG uid=%{uid} 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG [(1, 'schema-compat-entry-rdn', ['uid=%{uid}']), (0, 'schema-compat-entry-rdn', ['uid=%first("%{uid}")']), (0, 'schema-compat-entry-attribute', ['uid=%{uid}'])] 2020-06-03T06:39:49Z DEBUG Updated 1 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/80-schema_compat.update 0.244 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/81-externalmembers.update' 2020-06-03T06:39:49Z DEBUG Updating existing entry: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Initial value 2020-06-03T06:39:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG groups 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=groups 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=groups, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG memberUid=%{memberUid} 2020-06-03T06:39:49Z DEBUG memberUid=%deref_r("member","uid") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG addifexist: 'ipaexternalmember=%deref_r("member","ipaexternalmember")' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")'] 2020-06-03T06:39:49Z DEBUG addifexist: set schema-compat-entry-attribute to ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2020-06-03T06:39:49Z DEBUG addifexist: 'objectclass=ipaexternalgroup' to schema-compat-entry-attribute, current value ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")'] 2020-06-03T06:39:49Z DEBUG addifexist: set schema-compat-entry-attribute to ['objectclass=posixGroup', 'gidNumber=%{gidNumber}', 'memberUid=%{memberUid}', 'memberUid=%deref_r("member","uid")', '%ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","")', '%ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","")', 'ipaanchoruuid=%{ipaanchoruuid}', '%ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","")', 'ipaexternalmember=%deref_r("member","ipaexternalmember")', 'objectclass=ipaexternalgroup'] 2020-06-03T06:39:49Z DEBUG --------------------------------------------- 2020-06-03T06:39:49Z DEBUG Final value after applying updates 2020-06-03T06:39:49Z DEBUG dn: cn=groups,cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG objectClass: 2020-06-03T06:39:49Z DEBUG top 2020-06-03T06:39:49Z DEBUG extensibleObject 2020-06-03T06:39:49Z DEBUG cn: 2020-06-03T06:39:49Z DEBUG groups 2020-06-03T06:39:49Z DEBUG schema-compat-container-group: 2020-06-03T06:39:49Z DEBUG cn=compat, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-container-rdn: 2020-06-03T06:39:49Z DEBUG cn=groups 2020-06-03T06:39:49Z DEBUG schema-compat-search-base: 2020-06-03T06:39:49Z DEBUG cn=groups, cn=accounts, dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-search-filter: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG schema-compat-entry-rdn: 2020-06-03T06:39:49Z DEBUG cn=%{cn} 2020-06-03T06:39:49Z DEBUG schema-compat-entry-attribute: 2020-06-03T06:39:49Z DEBUG objectclass=posixGroup 2020-06-03T06:39:49Z DEBUG gidNumber=%{gidNumber} 2020-06-03T06:39:49Z DEBUG memberUid=%{memberUid} 2020-06-03T06:39:49Z DEBUG memberUid=%deref_r("member","uid") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG %ifeq("ipauniqueid","%{ipauniqueid}","ipaanchoruuid=:IPA:ipa.test:%{ipauniqueid}","") 2020-06-03T06:39:49Z DEBUG ipaanchoruuid=%{ipaanchoruuid} 2020-06-03T06:39:49Z DEBUG %ifeq("ipaanchoruuid","%{ipaanchoruuid}","objectclass=ipaOverrideTarget","") 2020-06-03T06:39:49Z DEBUG ipaexternalmember=%deref_r("member","ipaexternalmember") 2020-06-03T06:39:49Z DEBUG objectclass=ipaexternalgroup 2020-06-03T06:39:49Z DEBUG schema-compat-ignore-subtree: 2020-06-03T06:39:49Z DEBUG cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG schema-compat-restrict-subtree: 2020-06-03T06:39:49Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:49Z DEBUG cn=Schema Compatibility,cn=plugins,cn=config 2020-06-03T06:39:49Z DEBUG [(0, 'schema-compat-entry-attribute', ['ipaexternalmember=%deref_r("member","ipaexternalmember")', 'objectclass=ipaexternalgroup'])] 2020-06-03T06:39:49Z DEBUG Updated 1 2020-06-03T06:39:49Z DEBUG Done 2020-06-03T06:39:49Z DEBUG LDAP update duration: /usr/share/ipa/updates/81-externalmembers.update 0.016 sec 2020-06-03T06:39:49Z DEBUG Parsing update file '/usr/share/ipa/updates/90-post_upgrade_plugins.update' 2020-06-03T06:39:49Z DEBUG Executing upgrade plugin: update_ca_topology 2020-06-03T06:39:49Z DEBUG raw: update_ca_topology 2020-06-03T06:39:49Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:39:49Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:39:49Z DEBUG importing all plugin modules in ipaserver.plugins... 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.aci 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.automember 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.automount 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.baseldap 2020-06-03T06:39:49Z DEBUG ipaserver.plugins.baseldap is not a valid plugin module 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.baseuser 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.batch 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.ca 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.caacl 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.cert 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.certmap 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.certprofile 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.config 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.delegation 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.dns 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.dnsserver 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.dogtag 2020-06-03T06:39:49Z DEBUG skipping plugin module ipaserver.plugins.dogtag: dogtag not selected as RA plugin 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.domainlevel 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.group 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.hbac 2020-06-03T06:39:49Z DEBUG ipaserver.plugins.hbac is not a valid plugin module 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.hbacrule 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.hbacsvc 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.hbacsvcgroup 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.hbactest 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.host 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.hostgroup 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.idrange 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.idviews 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.internal 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.join 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.krbtpolicy 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.ldap2 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.location 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.migration 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.misc 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.netgroup 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.otp 2020-06-03T06:39:49Z DEBUG ipaserver.plugins.otp is not a valid plugin module 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.otpconfig 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.otptoken 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.passwd 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.permission 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.ping 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.pkinit 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.privilege 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.pwpolicy 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.rabase 2020-06-03T06:39:49Z DEBUG ipaserver.plugins.rabase is not a valid plugin module 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.radiusproxy 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.realmdomains 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.role 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.schema 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.selfservice 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.selinuxusermap 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.server 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.serverrole 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.serverroles 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.service 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.servicedelegation 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.session 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.stageuser 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.sudo 2020-06-03T06:39:49Z DEBUG ipaserver.plugins.sudo is not a valid plugin module 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.sudocmd 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.sudocmdgroup 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.sudorule 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.topology 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.trust 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.user 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.vault 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.virtual 2020-06-03T06:39:49Z DEBUG ipaserver.plugins.virtual is not a valid plugin module 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.whoami 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.plugins.xmlserver 2020-06-03T06:39:49Z DEBUG importing all plugin modules in ipaserver.install.plugins... 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.adtrust 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.ca_renewal_master 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.dns 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.fix_kra_people_entry 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.fix_replica_agreements 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.rename_managed 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_ca_topology 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_dna_shared_config 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_fix_duplicate_cacrt_in_ldap 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_idranges 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_ldap_server_list 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_managed_permissions 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_nis 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_pacs 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_passsync 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_ra_cert_store 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_referint 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_services 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_unhashed_password 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.update_uniqueness 2020-06-03T06:39:49Z DEBUG importing plugin module ipaserver.install.plugins.upload_cacrt 2020-06-03T06:39:50Z DEBUG Created connection context.ldap2_140690276686480 2020-06-03T06:39:50Z DEBUG Destroyed connection context.ldap2_140690276686480 2020-06-03T06:39:50Z DEBUG Created connection context.ldap2_140690276686480 2020-06-03T06:39:50Z DEBUG Parsing update file '/usr/share/ipa/ca-topology.uldif' 2020-06-03T06:39:50Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:39:50Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:39:50Z DEBUG Updating existing entry: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG --------------------------------------------- 2020-06-03T06:39:50Z DEBUG Initial value 2020-06-03T06:39:50Z DEBUG dn: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG objectClass: 2020-06-03T06:39:50Z DEBUG top 2020-06-03T06:39:50Z DEBUG nsContainer 2020-06-03T06:39:50Z DEBUG ipaReplTopoManagedServer 2020-06-03T06:39:50Z DEBUG ipaConfigObject 2020-06-03T06:39:50Z DEBUG ipaSupportedDomainLevelConfig 2020-06-03T06:39:50Z DEBUG cn: 2020-06-03T06:39:50Z DEBUG replica1.ipa.test 2020-06-03T06:39:50Z DEBUG ipaReplTopoManagedSuffix: 2020-06-03T06:39:50Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG o=ipaca 2020-06-03T06:39:50Z DEBUG ipaMinDomainLevel: 2020-06-03T06:39:50Z DEBUG 1 2020-06-03T06:39:50Z DEBUG ipaMaxDomainLevel: 2020-06-03T06:39:50Z DEBUG 1 2020-06-03T06:39:50Z DEBUG add: 'ipaReplTopoManagedServer' to objectclass, current value ['top', 'nsContainer', 'ipaReplTopoManagedServer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig'] 2020-06-03T06:39:50Z DEBUG add: updated value ['top', 'nsContainer', 'ipaConfigObject', 'ipaSupportedDomainLevelConfig', 'ipaReplTopoManagedServer'] 2020-06-03T06:39:50Z DEBUG add: 'o=ipaca' to ipaReplTopoManagedSuffix, current value ['dc=ipa,dc=test', 'o=ipaca'] 2020-06-03T06:39:50Z DEBUG add: updated value ['dc=ipa,dc=test', 'o=ipaca'] 2020-06-03T06:39:50Z DEBUG --------------------------------------------- 2020-06-03T06:39:50Z DEBUG Final value after applying updates 2020-06-03T06:39:50Z DEBUG dn: cn=replica1.ipa.test,cn=masters,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG objectClass: 2020-06-03T06:39:50Z DEBUG top 2020-06-03T06:39:50Z DEBUG nsContainer 2020-06-03T06:39:50Z DEBUG ipaConfigObject 2020-06-03T06:39:50Z DEBUG ipaSupportedDomainLevelConfig 2020-06-03T06:39:50Z DEBUG ipaReplTopoManagedServer 2020-06-03T06:39:50Z DEBUG cn: 2020-06-03T06:39:50Z DEBUG replica1.ipa.test 2020-06-03T06:39:50Z DEBUG ipaReplTopoManagedSuffix: 2020-06-03T06:39:50Z DEBUG dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG o=ipaca 2020-06-03T06:39:50Z DEBUG ipaMinDomainLevel: 2020-06-03T06:39:50Z DEBUG 1 2020-06-03T06:39:50Z DEBUG ipaMaxDomainLevel: 2020-06-03T06:39:50Z DEBUG 1 2020-06-03T06:39:50Z DEBUG [] 2020-06-03T06:39:50Z DEBUG Updated 0 2020-06-03T06:39:50Z DEBUG Done 2020-06-03T06:39:50Z DEBUG Updating existing entry: cn=ca,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG --------------------------------------------- 2020-06-03T06:39:50Z DEBUG Initial value 2020-06-03T06:39:50Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG cn: 2020-06-03T06:39:50Z DEBUG ca 2020-06-03T06:39:50Z DEBUG ipaReplTopoConfRoot: 2020-06-03T06:39:50Z DEBUG o=ipaca 2020-06-03T06:39:50Z DEBUG objectClass: 2020-06-03T06:39:50Z DEBUG top 2020-06-03T06:39:50Z DEBUG iparepltopoconf 2020-06-03T06:39:50Z DEBUG --------------------------------------------- 2020-06-03T06:39:50Z DEBUG Final value after applying updates 2020-06-03T06:39:50Z DEBUG dn: cn=ca,cn=topology,cn=ipa,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG cn: 2020-06-03T06:39:50Z DEBUG ca 2020-06-03T06:39:50Z DEBUG ipaReplTopoConfRoot: 2020-06-03T06:39:50Z DEBUG o=ipaca 2020-06-03T06:39:50Z DEBUG objectClass: 2020-06-03T06:39:50Z DEBUG top 2020-06-03T06:39:50Z DEBUG iparepltopoconf 2020-06-03T06:39:50Z DEBUG [] 2020-06-03T06:39:50Z DEBUG Updated 0 2020-06-03T06:39:50Z DEBUG Done 2020-06-03T06:39:50Z DEBUG Updating existing entry: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:39:50Z DEBUG --------------------------------------------- 2020-06-03T06:39:50Z DEBUG Initial value 2020-06-03T06:39:50Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:39:50Z DEBUG cn: 2020-06-03T06:39:50Z DEBUG replica 2020-06-03T06:39:50Z DEBUG nsDS5Flags: 2020-06-03T06:39:50Z DEBUG 1 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaBindDN: 2020-06-03T06:39:50Z DEBUG cn=replication manager,cn=config 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaBindDNGroup: 2020-06-03T06:39:50Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaBindDnGroupCheckInterval: 2020-06-03T06:39:50Z DEBUG 60 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaId: 2020-06-03T06:39:50Z DEBUG 5 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaName: 2020-06-03T06:39:50Z DEBUG 7cf5882d-a56411ea-9a6a937f-b7fd302f 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaRoot: 2020-06-03T06:39:50Z DEBUG o=ipaca 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaType: 2020-06-03T06:39:50Z DEBUG 3 2020-06-03T06:39:50Z DEBUG nsState: 2020-06-03T06:39:50Z DEBUG BQAAAAAAAACbRddeAAAAAAAAAAAAAAAAAAAAAAAAAAAJAAAAAAAAAA== 2020-06-03T06:39:50Z DEBUG nsds5ReplicaBackoffMax: 2020-06-03T06:39:50Z DEBUG 300 2020-06-03T06:39:50Z DEBUG nsds5ReplicaLegacyConsumer: 2020-06-03T06:39:50Z DEBUG off 2020-06-03T06:39:50Z DEBUG nsds5ReplicaReleaseTimeout: 2020-06-03T06:39:50Z DEBUG 60 2020-06-03T06:39:50Z DEBUG objectClass: 2020-06-03T06:39:50Z DEBUG top 2020-06-03T06:39:50Z DEBUG nsds5replica 2020-06-03T06:39:50Z DEBUG extensibleobject 2020-06-03T06:39:50Z DEBUG nsds5ReplicaChangeCount: 2020-06-03T06:39:50Z DEBUG 24 2020-06-03T06:39:50Z DEBUG nsds5replicareapactive: 2020-06-03T06:39:50Z DEBUG 0 2020-06-03T06:39:50Z DEBUG onlyifexist: 'cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test' to nsds5replicabinddngroup, current value ['cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:50Z DEBUG onlyifexist: set nsds5replicabinddngroup to ['cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test'] 2020-06-03T06:39:50Z DEBUG --------------------------------------------- 2020-06-03T06:39:50Z DEBUG Final value after applying updates 2020-06-03T06:39:50Z DEBUG dn: cn=replica,cn=o\=ipaca,cn=mapping tree,cn=config 2020-06-03T06:39:50Z DEBUG cn: 2020-06-03T06:39:50Z DEBUG replica 2020-06-03T06:39:50Z DEBUG nsDS5Flags: 2020-06-03T06:39:50Z DEBUG 1 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaBindDN: 2020-06-03T06:39:50Z DEBUG cn=replication manager,cn=config 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaBindDNGroup: 2020-06-03T06:39:50Z DEBUG cn=replication managers,cn=sysaccounts,cn=etc,dc=ipa,dc=test 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaBindDnGroupCheckInterval: 2020-06-03T06:39:50Z DEBUG 60 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaId: 2020-06-03T06:39:50Z DEBUG 5 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaName: 2020-06-03T06:39:50Z DEBUG 7cf5882d-a56411ea-9a6a937f-b7fd302f 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaRoot: 2020-06-03T06:39:50Z DEBUG o=ipaca 2020-06-03T06:39:50Z DEBUG nsDS5ReplicaType: 2020-06-03T06:39:50Z DEBUG 3 2020-06-03T06:39:50Z DEBUG nsState: 2020-06-03T06:39:50Z DEBUG BQAAAAAAAACbRddeAAAAAAAAAAAAAAAAAAAAAAAAAAAJAAAAAAAAAA== 2020-06-03T06:39:50Z DEBUG nsds5ReplicaBackoffMax: 2020-06-03T06:39:50Z DEBUG 300 2020-06-03T06:39:50Z DEBUG nsds5ReplicaLegacyConsumer: 2020-06-03T06:39:50Z DEBUG off 2020-06-03T06:39:50Z DEBUG nsds5ReplicaReleaseTimeout: 2020-06-03T06:39:50Z DEBUG 60 2020-06-03T06:39:50Z DEBUG objectClass: 2020-06-03T06:39:50Z DEBUG top 2020-06-03T06:39:50Z DEBUG nsds5replica 2020-06-03T06:39:50Z DEBUG extensibleobject 2020-06-03T06:39:50Z DEBUG nsds5ReplicaChangeCount: 2020-06-03T06:39:50Z DEBUG 24 2020-06-03T06:39:50Z DEBUG nsds5replicareapactive: 2020-06-03T06:39:50Z DEBUG 0 2020-06-03T06:39:50Z DEBUG [] 2020-06-03T06:39:50Z DEBUG Updated 0 2020-06-03T06:39:50Z DEBUG Done 2020-06-03T06:39:50Z DEBUG LDAP update duration: /usr/share/ipa/ca-topology.uldif 0.204 sec 2020-06-03T06:39:50Z DEBUG Destroyed connection context.ldap2_140690276686480 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_ipaconfigstring_dnsversion_to_ipadnsversion 2020-06-03T06:39:50Z DEBUG raw: update_ipaconfigstring_dnsversion_to_ipadnsversion 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_dnszones 2020-06-03T06:39:50Z DEBUG raw: update_dnszones 2020-06-03T06:39:50Z DEBUG raw: dnszone_find(None, all=True, version='2.236') 2020-06-03T06:39:50Z DEBUG dnszone_find(None, forward_only=False, all=True, raw=False, version='2.236', pkey_only=False) 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_dns_limits 2020-06-03T06:39:50Z DEBUG raw: update_dns_limits 2020-06-03T06:39:50Z DEBUG DNS: service krbprincipalname=DNS/replica1.ipa.test@IPA.TEST,cn=services,cn=accounts,dc=ipa,dc=test not found, no need to update limits 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_sigden_extdom_broken_config 2020-06-03T06:39:50Z DEBUG raw: update_sigden_extdom_broken_config 2020-06-03T06:39:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:50Z DEBUG configured basedn for cn=IPA SIDGEN,cn=plugins,cn=config is okay 2020-06-03T06:39:50Z DEBUG configured basedn for cn=ipa_extdom_extop,cn=plugins,cn=config is okay 2020-06-03T06:39:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:50Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_sids 2020-06-03T06:39:50Z DEBUG raw: update_sids 2020-06-03T06:39:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:50Z DEBUG SIDs do not need to be generated 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_default_range 2020-06-03T06:39:50Z DEBUG raw: update_default_range 2020-06-03T06:39:50Z DEBUG default_range: ipaDomainIDRange entry found, skip plugin 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_default_trust_view 2020-06-03T06:39:50Z DEBUG raw: update_default_trust_view 2020-06-03T06:39:50Z DEBUG raw: adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG AD Trusts are not enabled on this server 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_tdo_gidnumber 2020-06-03T06:39:50Z DEBUG raw: update_tdo_gidnumber 2020-06-03T06:39:50Z DEBUG raw: adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG AD Trusts are not enabled on this server 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_tdo_to_new_layout 2020-06-03T06:39:50Z DEBUG raw: update_tdo_to_new_layout 2020-06-03T06:39:50Z DEBUG raw: adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG AD Trusts are not enabled on this server 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_host_cifs_keytabs 2020-06-03T06:39:50Z DEBUG raw: update_host_cifs_keytabs 2020-06-03T06:39:50Z DEBUG raw: adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG AD Trusts are not enabled on this server 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_tdo_default_read_keys_permissions 2020-06-03T06:39:50Z DEBUG raw: update_tdo_default_read_keys_permissions 2020-06-03T06:39:50Z DEBUG raw: adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG AD Trusts are not enabled on this server 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_adtrust_agents_members 2020-06-03T06:39:50Z DEBUG raw: update_adtrust_agents_members 2020-06-03T06:39:50Z DEBUG raw: adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG adtrust_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG AD Trusts are not enabled on this server 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_ca_renewal_master 2020-06-03T06:39:50Z DEBUG raw: update_ca_renewal_master 2020-06-03T06:39:50Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:39:50Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:39:50Z DEBUG found CA renewal master master1.ipa.test 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_idrange_type 2020-06-03T06:39:50Z DEBUG raw: update_idrange_type 2020-06-03T06:39:50Z DEBUG update_idrange_type: search for ID ranges with no type set 2020-06-03T06:39:50Z DEBUG update_idrange_type: no ID range without type set found 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_pacs 2020-06-03T06:39:50Z DEBUG raw: update_pacs 2020-06-03T06:39:50Z DEBUG PAC for nfs is already set, not adding nfs:NONE. 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_service_principalalias 2020-06-03T06:39:50Z DEBUG raw: update_service_principalalias 2020-06-03T06:39:50Z DEBUG update_service_principalalias: search for affected services 2020-06-03T06:39:50Z DEBUG update_service_principalalias: found 3 services to update, truncated: False 2020-06-03T06:39:50Z DEBUG update_service_principalalias: all affected services updated 2020-06-03T06:39:50Z DEBUG Executing upgrade plugin: update_fix_duplicate_cacrt_in_ldap 2020-06-03T06:39:50Z DEBUG raw: update_fix_duplicate_cacrt_in_ldap 2020-06-03T06:39:50Z DEBUG raw: ca_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG ca_is_enabled(version='2.236') 2020-06-03T06:39:50Z DEBUG Found 1 entrie(s) for IPA CA in LDAP 2020-06-03T06:39:50Z DEBUG Destroyed connection context.ldap2_140690288004640 2020-06-03T06:39:50Z DEBUG Restarting directory server to apply updates 2020-06-03T06:39:50Z DEBUG Destroyed connection context.ldap2_140690310172784 2020-06-03T06:39:50Z DEBUG Starting external process 2020-06-03T06:39:50Z DEBUG args=['/sbin/systemctl', 'restart', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:39:55Z DEBUG Process finished, return code=0 2020-06-03T06:39:55Z DEBUG stdout= 2020-06-03T06:39:55Z DEBUG stderr= 2020-06-03T06:39:55Z DEBUG Restart of dirsrv@IPA-TEST.service complete 2020-06-03T06:39:55Z DEBUG Created connection context.ldap2_140690310172784 2020-06-03T06:39:55Z DEBUG Created connection context.ldap2_140690288004640 2020-06-03T06:39:55Z DEBUG Executing upgrade plugin: update_upload_cacrt 2020-06-03T06:39:55Z DEBUG raw: update_upload_cacrt 2020-06-03T06:39:55Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:39:55Z DEBUG raw: ca_is_enabled(version='2.236') 2020-06-03T06:39:55Z DEBUG ca_is_enabled(version='2.236') 2020-06-03T06:39:55Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:39:55Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:39:55Z DEBUG Starting external process 2020-06-03T06:39:55Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-IPA-TEST/', '-L', '-f', '/etc/dirsrv/slapd-IPA-TEST/pwdfile.txt'] 2020-06-03T06:39:55Z DEBUG Process finished, return code=0 2020-06-03T06:39:55Z DEBUG stdout= Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI IPA.TEST IPA CA CT,C,C Server-Cert u,u,u 2020-06-03T06:39:55Z DEBUG stderr= 2020-06-03T06:39:55Z DEBUG Starting external process 2020-06-03T06:39:55Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/dirsrv/slapd-IPA-TEST/', '-L', '-n', 'IPA.TEST IPA CA', '-a', '-f', '/etc/dirsrv/slapd-IPA-TEST/pwdfile.txt'] 2020-06-03T06:39:55Z DEBUG Process finished, return code=0 2020-06-03T06:39:55Z DEBUG stdout=-----BEGIN CERTIFICATE----- MIIEgjCCAuqgAwIBAgIBATANBgkqhkiG9w0BAQsFADAzMREwDwYDVQQKDAhJUEEu VEVTVDEeMBwGA1UEAwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MB4XDTIwMDYwMzA2 MjgxMFoXDTQwMDYwMzA2MjgxMFowMzERMA8GA1UECgwISVBBLlRFU1QxHjAcBgNV BAMMFUNlcnRpZmljYXRlIEF1dGhvcml0eTCCAaIwDQYJKoZIhvcNAQEBBQADggGP ADCCAYoCggGBAMr72aqrpeuoOHWdNFvpinjSsNjM1SmFM0fKvUplsX02bUmRiv8z ZiZZtTpbXQ8Fam2t28eM8dQzipv2hSGPIGzoiiTNPGTI8ahsNLSidhsqTaXd43Au Hw6AVB3RXEiXqBTRk5Dg9Zturmyv2fdmUIC1ELvf+B60zhqLgF/B7np1dagMuzUj 2BQ/bxF8Y3WLkYwxAC+hZmN/2IGxDanOzVicS+cSXiQM5nVIPMRnOID1wVlk6MZE gKX3D4UUXnJcGZeJoH1IKhGcjhdqMlZh1Rf6T5NGL6+b+LD1StwSRbFbjvQmHlJf t5byxfSpbtq30Td/njYhBNNNU7X7TQvdKfp86zd9xbU+8YLu08gjoNnlp0QQSeXy hvR5KsL1RxJtISaTfFmcS3y41YVY8d5l8XmpCjJe1CpjCGDI+r2daqQXahCap9kt UJl5l9rc4DI22zv92Xy41bc1NiENXOBPc5Uv1oqSfwv7BE3+t+GZzhajkvDDsUxy nwqY4Ljix/AfEwIDAQABo4GgMIGdMB8GA1UdIwQYMBaAFEPXeH/VSTVcEsFIBz7n GN/vUHZVMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgHGMB0GA1UdDgQW BBRD13h/1Uk1XBLBSAc+5xjf71B2VTA6BggrBgEFBQcBAQQuMCwwKgYIKwYBBQUH MAGGHmh0dHA6Ly9pcGEtY2EuaXBhLnRlc3QvY2Evb2NzcDANBgkqhkiG9w0BAQsF AAOCAYEAZJLiMwwqgiPor3BIk2taXVqKeLTKZkCzg4qqvJlA8YobcFGt9ptn1t4j 1vy4hMTDd7vmi04igKkX5FKeB5SNQFEva7iauGeQ8TZe6Sq3GP0TuijrXNVzMvUN OsXZKwwjrq/vAVvhLinkOfEiC9xZ+jh7KOlHhXB+gHbkGiLp//sZZ899dAP18DRz Xr6CFJqMFeecPPlwKFAl3wVdjG/Fin2tkC6Nx3mn5h/3lPp+ZMJpBxN7VZtJ4gDp k9ah+qc9/Y3OxyRkDl6qkP89aQlU8jCOL3IJnRG95QzvegEGwBxlTbO3VRYvdYWb FY25tGH9Kf8nrWnMmdGClSFlmOSnZkPss6Dq5KjXJ8nXY0HklX91G5g4ASiWcDih A4pPGyPLsS/Bq1z//CmyHbK9eN0OyskZhR7BEoYuJZz7HhdMho6sYQf4ozBoGGEa ujaa4HzE6vTW8O5VcpJp6XV9rrVqfUkLlUcTwurjmPKAETfOxD/jk1hvgT+8/Y9O GoU22kje -----END CERTIFICATE----- 2020-06-03T06:39:55Z DEBUG stderr= 2020-06-03T06:39:55Z DEBUG Executing upgrade plugin: update_ra_cert_store 2020-06-03T06:39:55Z DEBUG raw: update_ra_cert_store 2020-06-03T06:39:55Z DEBUG raw: ca_is_enabled(version='2.236') 2020-06-03T06:39:55Z DEBUG ca_is_enabled(version='2.236') 2020-06-03T06:39:55Z DEBUG Executing upgrade plugin: update_mapping_Guests_to_nobody 2020-06-03T06:39:55Z DEBUG raw: update_mapping_Guests_to_nobody 2020-06-03T06:39:55Z DEBUG raw: adtrust_is_enabled(version='2.236') 2020-06-03T06:39:55Z DEBUG adtrust_is_enabled(version='2.236') 2020-06-03T06:39:55Z DEBUG AD Trusts are not enabled on this server 2020-06-03T06:39:55Z DEBUG Executing upgrade plugin: fix_kra_people_entry 2020-06-03T06:39:55Z DEBUG raw: fix_kra_people_entry 2020-06-03T06:39:55Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:39:55Z DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2020-06-03T06:39:55Z DEBUG Executing upgrade plugin: update_master_to_dnsforwardzones 2020-06-03T06:39:55Z DEBUG raw: update_master_to_dnsforwardzones 2020-06-03T06:39:55Z DEBUG raw: dnsconfig_show(all=True, version='2.236') 2020-06-03T06:39:55Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version='2.236') 2020-06-03T06:39:55Z DEBUG Executing upgrade plugin: update_dnsforward_emptyzones 2020-06-03T06:39:55Z DEBUG raw: update_dnsforward_emptyzones 2020-06-03T06:39:55Z DEBUG raw: dnsconfig_show(all=True, version='2.236') 2020-06-03T06:39:55Z DEBUG dnsconfig_show(rights=False, all=True, raw=False, version='2.236') 2020-06-03T06:39:55Z DEBUG Executing upgrade plugin: update_managed_post 2020-06-03T06:39:55Z DEBUG raw: update_managed_post 2020-06-03T06:39:55Z DEBUG Executing upgrade plugin: update_managed_permissions 2020-06-03T06:39:55Z DEBUG raw: update_managed_permissions 2020-06-03T06:39:55Z DEBUG Anonymous ACI not found 2020-06-03T06:39:55Z DEBUG Updating managed permissions for automember 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Automember Definitions 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Automember Definitions 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Automember Rules 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Automember Rules 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Automember Tasks 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Automember Tasks 2020-06-03T06:39:55Z DEBUG Updating managed permissions for automountkey 2020-06-03T06:39:55Z DEBUG Legacy permission Add Automount keys not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Automount Keys 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Automount Keys 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Automount keys not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Automount Keys 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Automount Keys 2020-06-03T06:39:55Z DEBUG Legacy permission Remove Automount keys not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Automount Keys 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Automount Keys 2020-06-03T06:39:55Z DEBUG Updating managed permissions for automountlocation 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Automount Locations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Automount Locations 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Automount Configuration 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Automount Configuration 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Automount Locations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Automount Locations 2020-06-03T06:39:55Z DEBUG Updating managed permissions for automountmap 2020-06-03T06:39:55Z DEBUG Legacy permission Add Automount maps not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Automount Maps 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Automount Maps 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Automount maps not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Automount Maps 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Automount Maps 2020-06-03T06:39:55Z DEBUG Legacy permission Remove Automount maps not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Automount Maps 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Automount Maps 2020-06-03T06:39:55Z DEBUG Updating managed permissions for ca 2020-06-03T06:39:55Z DEBUG Legacy permission Add CA not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add CA 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add CA 2020-06-03T06:39:55Z DEBUG Legacy permission Delete CA not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete CA 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete CA 2020-06-03T06:39:55Z DEBUG Legacy permission Modify CA not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify CA 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify CA 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read CAs 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read CAs 2020-06-03T06:39:55Z DEBUG Updating managed permissions for caacl 2020-06-03T06:39:55Z DEBUG Legacy permission Add CA ACL not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add CA ACL 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add CA ACL 2020-06-03T06:39:55Z DEBUG Legacy permission Delete CA ACL not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete CA ACL 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete CA ACL 2020-06-03T06:39:55Z DEBUG Legacy permission Manage CA ACL membership not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage CA ACL Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage CA ACL Membership 2020-06-03T06:39:55Z DEBUG Legacy permission Modify CA ACL not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify CA ACL 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify CA ACL 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read CA ACLs 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read CA ACLs 2020-06-03T06:39:55Z DEBUG Updating managed permissions for certmapconfig 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Certmap Configuration 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Certmap Configuration 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Certmap Configuration 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Certmap Configuration 2020-06-03T06:39:55Z DEBUG Updating managed permissions for certmaprule 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Certmap Rules 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Certmap Rules 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete Certmap Rules 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete Certmap Rules 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Certmap Rules 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Certmap Rules 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Certmap Rules 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Certmap Rules 2020-06-03T06:39:55Z DEBUG Updating managed permissions for certprofile 2020-06-03T06:39:55Z DEBUG Legacy permission Delete Certificate Profile not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete Certificate Profile 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete Certificate Profile 2020-06-03T06:39:55Z DEBUG Legacy permission Import Certificate Profile not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Import Certificate Profile 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Import Certificate Profile 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Certificate Profile not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Certificate Profile 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Certificate Profile 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Certificate Profiles 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Certificate Profiles 2020-06-03T06:39:55Z DEBUG Updating managed permissions for config 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Global Configuration 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Global Configuration 2020-06-03T06:39:55Z DEBUG Updating managed permissions for cosentry 2020-06-03T06:39:55Z DEBUG Legacy permission Add Group Password Policy costemplate not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Group Password Policy costemplate 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Group Password Policy costemplate 2020-06-03T06:39:55Z DEBUG Legacy permission Delete Group Password Policy costemplate not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete Group Password Policy costemplate 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete Group Password Policy costemplate 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Group Password Policy costemplate not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Group Password Policy costemplate 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Group Password Policy costemplate 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Group Password Policy costemplate 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Group Password Policy costemplate 2020-06-03T06:39:55Z DEBUG Updating managed permissions for dnsconfig 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read DNS Configuration 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read DNS Configuration 2020-06-03T06:39:55Z DEBUG Legacy permission Write DNS Configuration not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Write DNS Configuration 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Write DNS Configuration 2020-06-03T06:39:55Z DEBUG Updating managed permissions for dnsserver 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify DNS Servers Configuration 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify DNS Servers Configuration 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read DNS Servers Configuration 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read DNS Servers Configuration 2020-06-03T06:39:55Z DEBUG Updating managed permissions for dnszone 2020-06-03T06:39:55Z DEBUG Legacy permission add dns entries not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add DNS Entries 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add DNS Entries 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage DNSSEC keys 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage DNSSEC keys 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage DNSSEC metadata 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage DNSSEC metadata 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read DNS Entries 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read DNS Entries 2020-06-03T06:39:55Z DEBUG Legacy permission 'Read DNS Entries' not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read DNSSEC metadata 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read DNSSEC metadata 2020-06-03T06:39:55Z DEBUG Legacy permission remove dns entries not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove DNS Entries 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove DNS Entries 2020-06-03T06:39:55Z DEBUG Legacy permission update dns entries not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Update DNS Entries 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Update DNS Entries 2020-06-03T06:39:55Z DEBUG Updating managed permissions for group 2020-06-03T06:39:55Z DEBUG Legacy permission Add Groups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Groups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Groups 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify External Group Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify External Group Membership 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Group membership not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Group Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Group Membership 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Groups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Groups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Groups 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read External Group Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read External Group Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Group Compat Tree 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Group Compat Tree 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Group Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Group Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Group Views Compat Tree 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Group Views Compat Tree 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Groups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Groups 2020-06-03T06:39:55Z DEBUG Legacy permission Remove Groups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Groups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Groups 2020-06-03T06:39:55Z DEBUG Updating managed permissions for hbacrule 2020-06-03T06:39:55Z DEBUG Legacy permission Add HBAC rule not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add HBAC Rule 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add HBAC Rule 2020-06-03T06:39:55Z DEBUG Legacy permission Delete HBAC rule not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete HBAC Rule 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete HBAC Rule 2020-06-03T06:39:55Z DEBUG Legacy permission Manage HBAC rule membership not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage HBAC Rule Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage HBAC Rule Membership 2020-06-03T06:39:55Z DEBUG Legacy permission Modify HBAC rule not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify HBAC Rule 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify HBAC Rule 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read HBAC Rules 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read HBAC Rules 2020-06-03T06:39:55Z DEBUG Updating managed permissions for hbacsvc 2020-06-03T06:39:55Z DEBUG Legacy permission Add HBAC services not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add HBAC Services 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add HBAC Services 2020-06-03T06:39:55Z DEBUG Legacy permission Delete HBAC services not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete HBAC Services 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete HBAC Services 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read HBAC Services 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read HBAC Services 2020-06-03T06:39:55Z DEBUG Updating managed permissions for hbacsvcgroup 2020-06-03T06:39:55Z DEBUG Legacy permission Add HBAC service groups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add HBAC Service Groups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add HBAC Service Groups 2020-06-03T06:39:55Z DEBUG Legacy permission Delete HBAC service groups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete HBAC Service Groups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete HBAC Service Groups 2020-06-03T06:39:55Z DEBUG Legacy permission Manage HBAC service group membership not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage HBAC Service Group Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage HBAC Service Group Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read HBAC Service Groups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read HBAC Service Groups 2020-06-03T06:39:55Z DEBUG Updating managed permissions for host 2020-06-03T06:39:55Z DEBUG Legacy permission Add Hosts not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Hosts 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Hosts 2020-06-03T06:39:55Z DEBUG Legacy permission Add krbPrincipalName to a host not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add krbPrincipalName to a Host 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add krbPrincipalName to a Host 2020-06-03T06:39:55Z DEBUG Legacy permission Enroll a host not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Enroll a Host 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Enroll a Host 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Host Certificates 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Host Certificates 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Host Enrollment Password 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Host Enrollment Password 2020-06-03T06:39:55Z DEBUG Legacy permission Manage host keytab not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Host Keytab 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Host Keytab 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Host Keytab Permissions 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Host Keytab Permissions 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Host Principals 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Host Principals 2020-06-03T06:39:55Z DEBUG Legacy permission Manage Host SSH Public Keys not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Host SSH Public Keys 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Host SSH Public Keys 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Hosts not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Hosts 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Hosts 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Host Compat Tree 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Host Compat Tree 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Host Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Host Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Hosts 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Hosts 2020-06-03T06:39:55Z DEBUG Legacy permission Remove Hosts not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Hosts 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Hosts 2020-06-03T06:39:55Z DEBUG Updating managed permissions for hostgroup 2020-06-03T06:39:55Z DEBUG Legacy permission Add Hostgroups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Hostgroups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Hostgroups 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Hostgroup membership not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Hostgroup Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Hostgroup Membership 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Hostgroups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Hostgroups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Hostgroups 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Hostgroup Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Hostgroup Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Hostgroups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Hostgroups 2020-06-03T06:39:55Z DEBUG Legacy permission Remove Hostgroups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Hostgroups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Hostgroups 2020-06-03T06:39:55Z DEBUG Updating managed permissions for idoverridegroup 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Group ID Overrides 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Group ID Overrides 2020-06-03T06:39:55Z DEBUG Updating managed permissions for idoverrideuser 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User ID Overrides 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User ID Overrides 2020-06-03T06:39:55Z DEBUG Updating managed permissions for idrange 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read ID Ranges 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read ID Ranges 2020-06-03T06:39:55Z DEBUG Updating managed permissions for idview 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read ID Views 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read ID Views 2020-06-03T06:39:55Z DEBUG Updating managed permissions for krbtpolicy 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Default Kerberos Ticket Policy 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Default Kerberos Ticket Policy 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User Kerberos Ticket Policy 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User Kerberos Ticket Policy 2020-06-03T06:39:55Z DEBUG Updating managed permissions for location 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add IPA Locations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add IPA Locations 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify IPA Locations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify IPA Locations 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read IPA Locations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read IPA Locations 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove IPA Locations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove IPA Locations 2020-06-03T06:39:55Z DEBUG Updating managed permissions for netgroup 2020-06-03T06:39:55Z DEBUG Legacy permission Add netgroups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Netgroups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Netgroups 2020-06-03T06:39:55Z DEBUG Legacy permission Modify netgroup membership not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Netgroup Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Netgroup Membership 2020-06-03T06:39:55Z DEBUG Legacy permission Modify netgroups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Netgroups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Netgroups 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Netgroup Compat Tree 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Netgroup Compat Tree 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Netgroup Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Netgroup Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Netgroups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Netgroups 2020-06-03T06:39:55Z DEBUG Legacy permission Remove netgroups not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Netgroups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Netgroups 2020-06-03T06:39:55Z DEBUG Updating managed permissions for otpconfig 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read OTP Configuration 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read OTP Configuration 2020-06-03T06:39:55Z DEBUG Updating managed permissions for permission 2020-06-03T06:39:55Z DEBUG Legacy permission Modify privilege membership not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Privilege Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Privilege Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read ACIs 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read ACIs 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Permissions 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Permissions 2020-06-03T06:39:55Z DEBUG Updating managed permissions for privilege 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Privileges 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Privileges 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Privileges 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Privileges 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Privileges 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Privileges 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Privileges 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Privileges 2020-06-03T06:39:55Z DEBUG Updating managed permissions for pwpolicy 2020-06-03T06:39:55Z DEBUG Legacy permission Add Group Password Policy not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Group Password Policy 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Group Password Policy 2020-06-03T06:39:55Z DEBUG Legacy permission Delete Group Password Policy not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete Group Password Policy 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete Group Password Policy 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Group Password Policy not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Group Password Policy 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Group Password Policy 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Group Password Policy 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Group Password Policy 2020-06-03T06:39:55Z DEBUG Updating managed permissions for radiusproxy 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Radius Servers 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Radius Servers 2020-06-03T06:39:55Z DEBUG Updating managed permissions for realmdomains 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Realm Domains 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Realm Domains 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Realm Domains 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Realm Domains 2020-06-03T06:39:55Z DEBUG Updating managed permissions for role 2020-06-03T06:39:55Z DEBUG Legacy permission Add Roles not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Roles 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Roles 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Role membership not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Role Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Role Membership 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Roles not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Roles 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Roles 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Roles 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Roles 2020-06-03T06:39:55Z DEBUG Legacy permission Remove Roles not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Roles 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Roles 2020-06-03T06:39:55Z DEBUG Updating managed permissions for selinuxusermap 2020-06-03T06:39:55Z DEBUG Legacy permission Add SELinux User Maps not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add SELinux User Maps 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add SELinux User Maps 2020-06-03T06:39:55Z DEBUG Legacy permission Modify SELinux User Maps not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify SELinux User Maps 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify SELinux User Maps 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read SELinux User Maps 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read SELinux User Maps 2020-06-03T06:39:55Z DEBUG Legacy permission Remove SELinux User Maps not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove SELinux User Maps 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove SELinux User Maps 2020-06-03T06:39:55Z DEBUG Updating managed permissions for server 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Locations of IPA Servers 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Locations of IPA Servers 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Status of Services on IPA Servers 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Status of Services on IPA Servers 2020-06-03T06:39:55Z DEBUG Updating managed permissions for service 2020-06-03T06:39:55Z DEBUG Legacy permission Add Services not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Services 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Services 2020-06-03T06:39:55Z DEBUG Legacy permission Manage service keytab not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Service Keytab 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Service Keytab 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Service Keytab Permissions 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Service Keytab Permissions 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Service Principals 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Service Principals 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Services not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Services 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Services 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read POSIX details of SMB services 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read POSIX details of SMB services 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Services 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Services 2020-06-03T06:39:55Z DEBUG Legacy permission Remove Services not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Services 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Services 2020-06-03T06:39:55Z DEBUG Updating managed permissions for servicedelegationrule 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Service Delegations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Service Delegations 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Service Delegation Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Service Delegations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Service Delegations 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Service Delegations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Service Delegations 2020-06-03T06:39:55Z DEBUG Updating managed permissions for servicedelegationtarget 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Service Delegations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Service Delegations 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Service Delegation Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Service Delegation Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Service Delegations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Service Delegations 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Service Delegations 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Service Delegations 2020-06-03T06:39:55Z DEBUG Updating managed permissions for stageuser 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Stage User 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Stage User 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Preserved Users 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Preserved Users 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Stage User 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Stage User 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify User RDN 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify User RDN 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Preserve User 2020-06-03T06:39:55Z DEBUG Updating ACI for managed permission: System: Preserve User 2020-06-03T06:39:55Z DEBUG Removing ACI '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from dc=ipa,dc=test 2020-06-03T06:39:55Z DEBUG Adding ACI '(target_to = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(target_from = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Preserve User";allow (moddn) groupdn = "ldap:///cn=System: Preserve User,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to dc=ipa,dc=test 2020-06-03T06:39:55Z DEBUG No changes to ACI 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Preserved Users 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Preserved Users 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Stage User password 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Stage User password 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Stage Users 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Stage Users 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Stage User 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Stage User 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove preserved User 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove preserved User 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Reset Preserved User password 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Reset Preserved User password 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Undelete User 2020-06-03T06:39:55Z DEBUG Updating ACI for managed permission: System: Undelete User 2020-06-03T06:39:55Z DEBUG Removing ACI '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)' from dc=ipa,dc=test 2020-06-03T06:39:55Z DEBUG Adding ACI '(target_to = "ldap:///cn=users,cn=accounts,dc=ipa,dc=test")(target_from = "ldap:///cn=deleted users,cn=accounts,cn=provisioning,dc=ipa,dc=test")(targetfilter = "(objectclass=nsContainer)")(version 3.0;acl "permission:System: Undelete User";allow (moddn) groupdn = "ldap:///cn=System: Undelete User,cn=permissions,cn=pbac,dc=ipa,dc=test";)' to dc=ipa,dc=test 2020-06-03T06:39:55Z DEBUG No changes to ACI 2020-06-03T06:39:55Z DEBUG Updating managed permissions for sudocmd 2020-06-03T06:39:55Z DEBUG Legacy permission Add Sudo command not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Sudo Command 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Sudo Command 2020-06-03T06:39:55Z DEBUG Legacy permission Delete Sudo command not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete Sudo Command 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete Sudo Command 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Sudo command not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Sudo Command 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Sudo Command 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Sudo Commands 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Sudo Commands 2020-06-03T06:39:55Z DEBUG Updating managed permissions for sudocmdgroup 2020-06-03T06:39:55Z DEBUG Legacy permission Add Sudo command group not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Sudo Command Group 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Sudo Command Group 2020-06-03T06:39:55Z DEBUG Legacy permission Delete Sudo command group not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete Sudo Command Group 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete Sudo Command Group 2020-06-03T06:39:55Z DEBUG Legacy permission Manage Sudo command group membership not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Sudo Command Group Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Sudo Command Group Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Sudo Command Group 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Sudo Command Group 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Sudo Command Groups 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Sudo Command Groups 2020-06-03T06:39:55Z DEBUG Updating managed permissions for sudorule 2020-06-03T06:39:55Z DEBUG Legacy permission Add Sudo rule not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Sudo rule 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Sudo rule 2020-06-03T06:39:55Z DEBUG Legacy permission Delete Sudo rule not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete Sudo rule 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete Sudo rule 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Sudo rule not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Sudo rule 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Sudo rule 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Sudo Rules 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Sudo Rules 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Sudoers compat tree 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Sudoers compat tree 2020-06-03T06:39:55Z DEBUG Updating managed permissions for trust 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Trust Information 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Trust Information 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read system trust accounts 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read system trust accounts 2020-06-03T06:39:55Z DEBUG Updating managed permissions for user 2020-06-03T06:39:55Z DEBUG Legacy permission Add user to default group not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add User to default group 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add User to default group 2020-06-03T06:39:55Z DEBUG Legacy permission Add Users not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Users 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Users 2020-06-03T06:39:55Z DEBUG Legacy permission Change a user password not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Change User password 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Change User password 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage User Certificate Mappings 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage User Certificate Mappings 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage User Certificates 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage User Certificates 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage User Principals 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage User Principals 2020-06-03T06:39:55Z DEBUG Legacy permission Manage User SSH Public Keys not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage User SSH Public Keys 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage User SSH Public Keys 2020-06-03T06:39:55Z DEBUG Legacy permission Modify Users not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Users 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Users 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read UPG Definition 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read UPG Definition 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User Addressbook Attributes 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User Addressbook Attributes 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User Compat Tree 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User Compat Tree 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User IPA Attributes 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User IPA Attributes 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User Kerberos Attributes 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User Kerberos Attributes 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User Kerberos Login Attributes 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User Kerberos Login Attributes 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User NT Attributes 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User NT Attributes 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User Standard Attributes 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User Standard Attributes 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read User Views Compat Tree 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read User Views Compat Tree 2020-06-03T06:39:55Z DEBUG Legacy permission Remove Users not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Remove Users 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Remove Users 2020-06-03T06:39:55Z DEBUG Legacy permission Unlock user accounts not found 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Unlock User 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Unlock User 2020-06-03T06:39:55Z DEBUG Updating managed permissions for vault 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Vaults 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Vaults 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete Vaults 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete Vaults 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Vault Membership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Vault Membership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Vault Ownership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Vault Ownership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Vaults 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Vaults 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Vaults 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Vaults 2020-06-03T06:39:55Z DEBUG Updating managed permissions for vaultcontainer 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Vault Containers 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Vault Containers 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Delete Vault Containers 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Delete Vault Containers 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Manage Vault Container Ownership 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Manage Vault Container Ownership 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Vault Containers 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Vault Containers 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Vault Containers 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Vault Containers 2020-06-03T06:39:55Z DEBUG Updating non-object managed permissions 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add CA Certificate For Renewal 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add CA Certificate For Renewal 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Add Certificate Store Entry 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Add Certificate Store Entry 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Compat Tree ID View targets 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Compat Tree ID View targets 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify CA Certificate 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify CA Certificate 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify CA Certificate For Renewal 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify CA Certificate For Renewal 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Modify Certificate Store Entry 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Modify Certificate Store Entry 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read AD Domains 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read AD Domains 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read CA Certificate 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read CA Certificate 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read CA Renewal Information 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read CA Renewal Information 2020-06-03T06:39:55Z DEBUG Updating managed permission: System: Read Certificate Store Entries 2020-06-03T06:39:55Z DEBUG No changes to permission: System: Read Certificate Store Entries 2020-06-03T06:39:56Z DEBUG Updating managed permission: System: Read DNA Configuration 2020-06-03T06:39:56Z DEBUG No changes to permission: System: Read DNA Configuration 2020-06-03T06:39:56Z DEBUG Updating managed permission: System: Read DUA Profile 2020-06-03T06:39:56Z DEBUG No changes to permission: System: Read DUA Profile 2020-06-03T06:39:56Z DEBUG Updating managed permission: System: Read Domain Level 2020-06-03T06:39:56Z DEBUG No changes to permission: System: Read Domain Level 2020-06-03T06:39:56Z DEBUG Updating managed permission: System: Read IPA Masters 2020-06-03T06:39:56Z DEBUG No changes to permission: System: Read IPA Masters 2020-06-03T06:39:56Z DEBUG Updating managed permission: System: Read Replication Information 2020-06-03T06:39:56Z DEBUG No changes to permission: System: Read Replication Information 2020-06-03T06:39:56Z DEBUG Updating managed permission: System: Remove Certificate Store Entry 2020-06-03T06:39:56Z DEBUG No changes to permission: System: Remove Certificate Store Entry 2020-06-03T06:39:56Z DEBUG Deleting obsolete permission System: Read Timestamp and USN Operational Attributes 2020-06-03T06:39:56Z DEBUG raw: permission_del(('System: Read Timestamp and USN Operational Attributes',), force=True, version='2.101') 2020-06-03T06:39:56Z DEBUG permission_del(('System: Read Timestamp and USN Operational Attributes',), continue=False, force=True, version='2.101') 2020-06-03T06:39:56Z DEBUG Obsolete permission not found 2020-06-03T06:39:56Z DEBUG Deleting obsolete permission System: Read Creator and Modifier Operational Attributes 2020-06-03T06:39:56Z DEBUG raw: permission_del(('System: Read Creator and Modifier Operational Attributes',), force=True, version='2.101') 2020-06-03T06:39:56Z DEBUG permission_del(('System: Read Creator and Modifier Operational Attributes',), continue=False, force=True, version='2.101') 2020-06-03T06:39:56Z DEBUG Obsolete permission not found 2020-06-03T06:39:56Z DEBUG Executing upgrade plugin: update_read_replication_agreements_permission 2020-06-03T06:39:56Z DEBUG raw: update_read_replication_agreements_permission 2020-06-03T06:39:56Z DEBUG Old permission not found 2020-06-03T06:39:56Z DEBUG Executing upgrade plugin: update_idrange_baserid 2020-06-03T06:39:56Z DEBUG raw: update_idrange_baserid 2020-06-03T06:39:56Z DEBUG update_idrange_baserid: search for ipa-ad-trust-posix ID ranges with ipaBaseRID != 0 2020-06-03T06:39:56Z DEBUG update_idrange_baserid: no AD domain range with posix attributes found 2020-06-03T06:39:56Z DEBUG Executing upgrade plugin: update_passync_privilege_update 2020-06-03T06:39:56Z DEBUG raw: update_passync_privilege_update 2020-06-03T06:39:56Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:56Z DEBUG PassSync privilege update not needed 2020-06-03T06:39:56Z DEBUG Executing upgrade plugin: update_dnsserver_configuration_into_ldap 2020-06-03T06:39:56Z DEBUG raw: update_dnsserver_configuration_into_ldap 2020-06-03T06:39:56Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:56Z DEBUG raw: server_show('replica1.ipa.test', version='2.236') 2020-06-03T06:39:56Z DEBUG server_show('replica1.ipa.test', rights=False, all=False, raw=False, version='2.236', no_members=False) 2020-06-03T06:39:56Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.236') 2020-06-03T06:39:56Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.236', pkey_only=False) 2020-06-03T06:39:56Z DEBUG raw: server_role_find(None, server_server='replica1.ipa.test', status='enabled', include_master=True, version='2.236') 2020-06-03T06:39:56Z DEBUG server_role_find(None, server_server='replica1.ipa.test', status='enabled', include_master=True, all=False, raw=False, version='2.236') 2020-06-03T06:39:56Z DEBUG This server is not DNS server, nothing to upgrade 2020-06-03T06:39:56Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:56Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:39:56Z DEBUG Executing upgrade plugin: update_ldap_server_list 2020-06-03T06:39:56Z DEBUG raw: update_ldap_server_list 2020-06-03T06:39:56Z DEBUG Executing upgrade plugin: update_dna_shared_config 2020-06-03T06:39:56Z DEBUG raw: update_dna_shared_config 2020-06-03T06:39:56Z DEBUG 2 entries dnaHostname=replica1.ipa.test under cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=ipa,dc=test. One expected 2020-06-03T06:39:56Z DEBUG Executing upgrade plugin: update_unhashed_password 2020-06-03T06:39:56Z DEBUG raw: update_unhashed_password 2020-06-03T06:39:56Z DEBUG Upgrading unhashed password configuration 2020-06-03T06:39:56Z DEBUG Unhashed password this is not a winsync deployment 2020-06-03T06:39:56Z DEBUG LDAP update duration: /usr/share/ipa/updates/90-post_upgrade_plugins.update 6.673 sec 2020-06-03T06:39:56Z DEBUG Destroyed connection context.ldap2_140690288004640 2020-06-03T06:39:56Z DEBUG step duration: dirsrv __upgrade 22.62 sec 2020-06-03T06:39:56Z DEBUG [8/10]: stopping directory server 2020-06-03T06:39:56Z DEBUG Destroyed connection context.ldap2_140690310172784 2020-06-03T06:39:56Z DEBUG Starting external process 2020-06-03T06:39:56Z DEBUG args=['/sbin/systemctl', 'stop', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:40:02Z DEBUG Process finished, return code=0 2020-06-03T06:40:02Z DEBUG stdout= 2020-06-03T06:40:02Z DEBUG stderr= 2020-06-03T06:40:02Z DEBUG Stop of dirsrv@IPA-TEST.service complete 2020-06-03T06:40:02Z DEBUG step duration: dirsrv __stop_instance 6.52 sec 2020-06-03T06:40:02Z DEBUG [9/10]: restoring configuration 2020-06-03T06:40:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:40:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:40:02Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:40:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:40:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:40:02Z DEBUG Saving StateFile to '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:40:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:40:02Z DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2020-06-03T06:40:02Z DEBUG step duration: dirsrv __restore_config 0.06 sec 2020-06-03T06:40:02Z DEBUG [10/10]: starting directory server 2020-06-03T06:40:02Z DEBUG Starting external process 2020-06-03T06:40:02Z DEBUG args=['/sbin/systemctl', 'start', 'dirsrv@IPA-TEST.service'] 2020-06-03T06:40:05Z DEBUG Process finished, return code=0 2020-06-03T06:40:05Z DEBUG stdout= 2020-06-03T06:40:05Z DEBUG stderr= 2020-06-03T06:40:05Z DEBUG Start of dirsrv@IPA-TEST.service complete 2020-06-03T06:40:05Z DEBUG Created connection context.ldap2_140690310172784 2020-06-03T06:40:05Z DEBUG step duration: dirsrv __start 3.33 sec 2020-06-03T06:40:05Z DEBUG Done. 2020-06-03T06:40:05Z DEBUG service duration: dirsrv 37.21 sec 2020-06-03T06:40:05Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:40:05Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:40:05Z DEBUG Loading StateFile from '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:40:05Z DEBUG Saving StateFile to '/var/lib/ipa/sysupgrade/sysupgrade.state' 2020-06-03T06:40:05Z DEBUG Finalize replication settings 2020-06-03T06:40:06Z DEBUG Restarting the KDC 2020-06-03T06:40:06Z DEBUG Starting external process 2020-06-03T06:40:06Z DEBUG args=['/sbin/systemctl', 'restart', 'krb5kdc.service'] 2020-06-03T06:40:06Z DEBUG Process finished, return code=0 2020-06-03T06:40:06Z DEBUG stdout= 2020-06-03T06:40:06Z DEBUG stderr= 2020-06-03T06:40:06Z DEBUG Starting external process 2020-06-03T06:40:06Z DEBUG args=['/sbin/systemctl', 'is-active', 'krb5kdc.service'] 2020-06-03T06:40:06Z DEBUG Process finished, return code=0 2020-06-03T06:40:06Z DEBUG stdout=active 2020-06-03T06:40:06Z DEBUG stderr= 2020-06-03T06:40:06Z DEBUG Restart of krb5kdc.service complete 2020-06-03T06:40:06Z DEBUG Waiting up to 300 seconds to see our keys appear on host ldap://master1.ipa.test 2020-06-03T06:40:06Z DEBUG Starting new HTTPS connection (1): master1.ipa.test:443 2020-06-03T06:40:06Z DEBUG https://master1.ipa.test:443 "GET /ipa/keys/dm/DMHash?type=kem&value=eyJhbGciOiJSU0EtT0FFUCIsImVuYyI6IkEyNTZDQkMtSFM1MTIiLCJraWQiOm51bGx9.lm0_DsW90PUeOIUnkhY4IvCohAZzpKP09Rh_ay07sPwGXmE8UssRkytVAHBLOb5QkVnk3UxHwQVrB9JDgFJ32AAr0T4IzUskKJfiaIb08Ojo8BvDcNIW22_lIVE893a4JsD_n2gyVm8XCFdjewOt5Z8RNF10vJEalH4lHZ6RXtBy7advQSowt9lXepUEovjQ3NQ0Di3MMatUsPhbWGAXts0MJ_0LPhv90QyvfeCwxJyQtaQeBpYbu0hsQcjNcVr_ojrBUBNiEqZBH_iBwtQogdK_q_Usw0wadQBJnsJUfLPCXHUiX-ypctTmR7Wfy_V_hGEn1HgmYsiFNtnDvEDw9A.vFsr8gMOi9t_YWhXgAUlSw.-xm2q6VeSDKRhipet1fu-GtIQh73WtUJPOu0yyNqvLjby5vpUn7IVcYzxfvoyBYmTCggzmdCRsTApQtH8htOwXHSm3rtzbJ98hOdEDpFDEVwWY8Brfrhs0Iv62OMOYh2RCk3CwCsTzhzbf6nnvUDG4hfFaeRZvTDI1j68NcIW6M_cnxvX6XnsBgLFqdENm1qg5Gn-v5d2NMqSfuOM4OuO_LNeL4GaFBUBUoqd0WKOEYawbfXGdEKvdAMocbUm40NRzI112yiOg2OypXk3I0_4AFJN-dilLoadTPLetRW34_OgWTpiMWsbGCuhEJZqdcFEl_QSqkD9XHYpdHNoClspueg6ohM2xUxe-ziY_ELvm4AwmiJzYiKDwYK_2oR3nY4IqJ1P9YAMB2ofVWjhXl2cD_hbj6vt43x8nXjMAahPYzgJXdhi3cTKuaDbcTH47r1_rJWm34EwRBRxgTa0_nLzH07jk1rsMT0T1CyB0x__oSYZ9FcpxpVumCSdwiHT1yFtD3kWcI3DnZSdC3ZnIG_5hS2qQ3_ZU_ZP-1v0994cPuS3hYVmAfmBH7DCwh792J5bU-76tbZlix6wb3C7wLWPpGwsGkqZE4x71yu5uKtxTkaTH4bq7TLB24JOYApTUrX.aqyn0g0zDGHGKLT60nKtJxGcEk8ORCh4xGA7petDIBY HTTP/1.1" 200 1544 2020-06-03T06:40:06Z DEBUG Starting external process 2020-06-03T06:40:06Z DEBUG args=['/usr/libexec/ipa/custodia/ipa-custodia-dmldap', '--import', '-'] 2020-06-03T06:40:07Z DEBUG Process finished, return code=0 2020-06-03T06:40:07Z DEBUG stdout= 2020-06-03T06:40:07Z DEBUG stderr= 2020-06-03T06:40:07Z DEBUG Starting external process 2020-06-03T06:40:07Z DEBUG args=['/sbin/systemctl', 'restart', 'sssd.service'] 2020-06-03T06:40:07Z DEBUG Process finished, return code=0 2020-06-03T06:40:07Z DEBUG stdout= 2020-06-03T06:40:07Z DEBUG stderr= 2020-06-03T06:40:07Z DEBUG Starting external process 2020-06-03T06:40:07Z DEBUG args=['/sbin/systemctl', 'is-active', 'sssd.service'] 2020-06-03T06:40:07Z DEBUG Process finished, return code=0 2020-06-03T06:40:07Z DEBUG stdout=active 2020-06-03T06:40:07Z DEBUG stderr= 2020-06-03T06:40:07Z DEBUG Restart of sssd.service complete 2020-06-03T06:40:07Z DEBUG Writing configuration file /etc/openldap/ldap.conf 2020-06-03T06:40:07Z DEBUG # File modified by ipa-client-install # We do not want to break your existing configuration, hence: # URI, BASE, TLS_CACERT and SASL_MECH # have been added if they were not set. # In case any of them were set, a comment has been inserted and # "# CONF_NAME modified by IPA" added to the line above. # To use IPA server with openLDAP tools, please comment out your # existing configuration for these options and uncomment the # corresponding lines generated by IPA. # # LDAP Defaults # # See ldap.conf(5) for details # This file should be world readable but not world writable. #BASE dc=example,dc=com #URI ldap://ldap.example.com ldap://ldap-master.example.com:666 #SIZELIMIT 12 #TIMELIMIT 15 #DEREF never BASE dc=ipa,dc=test TLS_CACERT /etc/ipa/ca.crt SASL_MECH GSSAPI 2020-06-03T06:40:07Z DEBUG Updating configuration file /etc/openldap/ldap.conf 2020-06-03T06:40:07Z DEBUG # File modified by ipa-client-install # We do not want to break your existing configuration, hence: # URI, BASE, TLS_CACERT and SASL_MECH # have been added if they were not set. # In case any of them were set, a comment has been inserted and # "# CONF_NAME modified by IPA" added to the line above. # To use IPA server with openLDAP tools, please comment out your # existing configuration for these options and uncomment the # corresponding lines generated by IPA. # # LDAP Defaults # # See ldap.conf(5) for details # This file should be world readable but not world writable. #BASE dc=example,dc=com #URI ldap://ldap.example.com ldap://ldap-master.example.com:666 #SIZELIMIT 12 #TIMELIMIT 15 #DEREF never BASE dc=ipa,dc=test TLS_CACERT /etc/ipa/ca.crt SASL_MECH GSSAPI URI ldaps://replica1.ipa.test 2020-06-03T06:40:07Z DEBUG flushing ldapi://%2Frun%2Fslapd-IPA-TEST.socket from SchemaCache 2020-06-03T06:40:07Z DEBUG retrieving schema for SchemaCache url=ldapi://%2Frun%2Fslapd-IPA-TEST.socket conn= 2020-06-03T06:40:08Z DEBUG Set service ['KDC'] for replica1.ipa.test to enabledService 2020-06-03T06:40:08Z DEBUG Set service ['KPASSWD'] for replica1.ipa.test to enabledService 2020-06-03T06:40:08Z DEBUG Set service ['HTTP'] for replica1.ipa.test to enabledService 2020-06-03T06:40:08Z DEBUG Set service ['OTPD'] for replica1.ipa.test to enabledService 2020-06-03T06:40:08Z DEBUG Set service ['KEYS'] for replica1.ipa.test to enabledService 2020-06-03T06:40:08Z DEBUG Set service ['CA'] for replica1.ipa.test to enabledService 2020-06-03T06:40:08Z DEBUG raw: dns_update_system_records(version='2.236') 2020-06-03T06:40:08Z DEBUG dns_update_system_records(dry_run=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: server_find(None, version='2.236', no_members=False, servrole='IPA master') 2020-06-03T06:40:08Z DEBUG server_find(None, all=False, raw=False, version='2.236', no_members=False, pkey_only=False, servrole=('IPA master',)) 2020-06-03T06:40:08Z DEBUG raw: server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, version='2.236') 2020-06-03T06:40:08Z DEBUG server_role_find(None, server_server=None, role_servrole='IPA master', status='enabled', include_master=True, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: topologysuffix_find(None, all=True, raw=True, version='2.236') 2020-06-03T06:40:08Z DEBUG topologysuffix_find(None, all=True, raw=True, version='2.236', pkey_only=False) 2020-06-03T06:40:08Z DEBUG raw: server_role_find(None, server_server='master1.ipa.test', status='enabled', include_master=True, version='2.236') 2020-06-03T06:40:08Z DEBUG server_role_find(None, server_server='master1.ipa.test', status='enabled', include_master=True, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: server_role_find(None, server_server='replica1.ipa.test', status='enabled', include_master=True, version='2.236') 2020-06-03T06:40:08Z DEBUG server_role_find(None, server_server='replica1.ipa.test', status='enabled', include_master=True, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: dnszone_show(, version='2.236') 2020-06-03T06:40:08Z DEBUG dnszone_show(, rights=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG found 1 1 records for master1.ipa.test.: 172.18.0.2 2020-06-03T06:40:08Z DEBUG The DNS response does not contain an answer to the question: master1.ipa.test. IN AAAA 2020-06-03T06:40:08Z DEBUG found 1 1 records for replica1.ipa.test.: 172.18.0.4 2020-06-03T06:40:08Z DEBUG The DNS response does not contain an answer to the question: replica1.ipa.test. IN AAAA 2020-06-03T06:40:08Z DEBUG raw: dnsrecord_mod(, , txtrecord=['"IPA.TEST"'], version='2.236') 2020-06-03T06:40:08Z DEBUG dnsrecord_mod(, , txtrecord=('"IPA.TEST"',), rights=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 389 master1.ipa.test.', '0 100 389 replica1.ipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.236') 2020-06-03T06:40:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 389 master1.ipa.test.', '0 100 389 replica1.ipa.test.'), setattr=('idnsTemplateAttribute;cnamerecord=_ldap._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master1.ipa.test.', '0 100 88 replica1.ipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.236') 2020-06-03T06:40:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master1.ipa.test.', '0 100 88 replica1.ipa.test.'), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master1.ipa.test.', '0 100 88 replica1.ipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.236') 2020-06-03T06:40:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master1.ipa.test.', '0 100 88 replica1.ipa.test.'), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master1.ipa.test.', '0 100 88 replica1.ipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.236') 2020-06-03T06:40:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master1.ipa.test.', '0 100 88 replica1.ipa.test.'), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 88 master1.ipa.test.', '0 100 88 replica1.ipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.236') 2020-06-03T06:40:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 88 master1.ipa.test.', '0 100 88 replica1.ipa.test.'), setattr=('idnsTemplateAttribute;cnamerecord=_kerberos-master._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 master1.ipa.test.', '0 100 464 replica1.ipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.236') 2020-06-03T06:40:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 master1.ipa.test.', '0 100 464 replica1.ipa.test.'), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._tcp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: dnsrecord_mod(, , srvrecord=['0 100 464 master1.ipa.test.', '0 100 464 replica1.ipa.test.'], setattr=['idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations'], addattr=['objectclass=idnsTemplateObject'], version='2.236') 2020-06-03T06:40:08Z DEBUG dnsrecord_mod(, , srvrecord=('0 100 464 master1.ipa.test.', '0 100 464 replica1.ipa.test.'), setattr=('idnsTemplateAttribute;cnamerecord=_kpasswd._udp.\\{substitutionvariable_ipalocation\\}._locations',), addattr=('objectclass=idnsTemplateObject',), rights=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: dnsrecord_mod(, , arecord=['172.18.0.2', '172.18.0.4'], version='2.236') 2020-06-03T06:40:08Z DEBUG dnsrecord_mod(, , arecord=('172.18.0.2', '172.18.0.4'), rights=False, structured=False, all=False, raw=False, version='2.236') 2020-06-03T06:40:08Z DEBUG raw: location_find(None, version='2.236') 2020-06-03T06:40:08Z DEBUG location_find(None, all=False, raw=False, version='2.236', pkey_only=False) 2020-06-03T06:40:08Z DEBUG Destroyed connection context.ldap2_140690310172784 2020-06-03T06:40:08Z DEBUG Starting external process 2020-06-03T06:40:08Z DEBUG args=['/sbin/systemctl', 'enable', 'ipa.service'] 2020-06-03T06:40:08Z DEBUG Process finished, return code=0 2020-06-03T06:40:08Z DEBUG stdout= 2020-06-03T06:40:08Z DEBUG stderr=Created symlink /etc/systemd/system/multi-user.target.wants/ipa.service → /lib/systemd/system/ipa.service. 2020-06-03T06:40:08Z DEBUG Starting external process 2020-06-03T06:40:08Z DEBUG args=['/sbin/systemctl', 'restart', 'ipa.service'] 2020-06-03T06:40:10Z DEBUG Process finished, return code=0 2020-06-03T06:40:10Z DEBUG stdout= 2020-06-03T06:40:10Z DEBUG stderr= 2020-06-03T06:40:10Z DEBUG Starting external process 2020-06-03T06:40:10Z DEBUG args=['/sbin/systemctl', 'is-active', 'ipa.service'] 2020-06-03T06:40:10Z DEBUG Process finished, return code=0 2020-06-03T06:40:10Z DEBUG stdout=active 2020-06-03T06:40:10Z DEBUG stderr= 2020-06-03T06:40:10Z DEBUG Restart of ipa.service complete 2020-06-03T06:40:10Z INFO The ipa-replica-install command was successful