Skip to content

Instantly share code, notes, and snippets.

@ZPrimed
Created February 18, 2021 06:59
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save ZPrimed/1040499a744286690745a7d93bcd3d10 to your computer and use it in GitHub Desktop.
Save ZPrimed/1040499a744286690745a7d93bcd3d10 to your computer and use it in GitHub Desktop.
ipaclient-install.log from Ubuntu 20.04 LTS -- claims success but doesn't work
2021-02-18T04:46:20Z DEBUG Logging to /var/log/ipaclient-install.log
2021-02-18T04:46:20Z DEBUG ipa-client-install was invoked with arguments [] and options: {'unattended': False, 'principal': None, 'prompt_password': False, 'on_master': False, 'ca_cert_files': None, 'force': False, 'configure_firefox': False, 'firefox_dir': None, 'keytab': None, 'mkhomedir': True, 'force_join': False, 'ntp_servers': None, 'ntp_pool': None, 'no_ntp': False, 'force_ntpd': False, 'nisdomain': None, 'no_nisdomain': False, 'ssh_trust_dns': False, 'no_ssh': False, 'no_sshd': False, 'no_sudo': False, 'no_dns_sshfp': False, 'kinit_attempts': None, 'request_cert': False, 'ip_addresses': None, 'all_ip_addresses': False, 'fixed_primary': False, 'permit': False, 'enable_dns_updates': False, 'no_krb5_offline_passwords': False, 'preserve_sssd': False, 'automount_location': None, 'domain_name': None, 'servers': None, 'realm_name': None, 'host_name': None, 'verbose': False, 'quiet': False, 'log_file': None, 'uninstall': False}
2021-02-18T04:46:20Z DEBUG IPA version 4.8.6
2021-02-18T04:46:20Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index'
2021-02-18T04:46:20Z DEBUG Starting external process
2021-02-18T04:46:20Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:20Z DEBUG Process execution failed
2021-02-18T04:46:20Z DEBUG Deleting invalid keytab: '/etc/krb5.keytab'.
2021-02-18T04:46:20Z DEBUG [IPA Discovery]
2021-02-18T04:46:20Z DEBUG Starting IPA discovery with domain=None, servers=None, hostname=gamma.example.org
2021-02-18T04:46:20Z DEBUG Start searching for LDAP SRV record in "example.org" (domain of the hostname) and its sub-domains
2021-02-18T04:46:20Z DEBUG Search DNS for SRV record of _ldap._tcp.example.org
2021-02-18T04:46:20Z DEBUG DNS record found: 0 100 389 ipa3.example.org.
2021-02-18T04:46:20Z DEBUG DNS record found: 0 100 389 ipa2.example.org.
2021-02-18T04:46:20Z DEBUG DNS record found: 0 100 389 ipa1.example.org.
2021-02-18T04:46:20Z DEBUG [Kerberos realm search]
2021-02-18T04:46:20Z DEBUG Search DNS for TXT record of _kerberos.example.org
2021-02-18T04:46:20Z DEBUG DNS record found: "EXAMPLE.ORG"
2021-02-18T04:46:20Z DEBUG Search DNS for SRV record of _kerberos._udp.example.org
2021-02-18T04:46:20Z DEBUG DNS record found: 0 100 88 ipa2.example.org.
2021-02-18T04:46:20Z DEBUG DNS record found: 0 100 88 ipa3.example.org.
2021-02-18T04:46:20Z DEBUG DNS record found: 0 100 88 ipa1.example.org.
2021-02-18T04:46:20Z DEBUG [LDAP server check]
2021-02-18T04:46:20Z DEBUG Verifying that ipa3.example.org (realm EXAMPLE.ORG) is an IPA server
2021-02-18T04:46:20Z DEBUG Init LDAP connection to: ldap://ipa3.example.org:389
2021-02-18T04:46:20Z DEBUG Search LDAP server for IPA base DN
2021-02-18T04:46:20Z DEBUG Check if naming context 'dc=example,dc=org' is for IPA
2021-02-18T04:46:20Z DEBUG Naming context 'dc=example,dc=org' is a valid IPA context
2021-02-18T04:46:20Z DEBUG Search for (objectClass=krbRealmContainer) in dc=example,dc=org (sub)
2021-02-18T04:46:20Z DEBUG Found: cn=EXAMPLE.ORG,cn=kerberos,dc=example,dc=org
2021-02-18T04:46:20Z DEBUG Discovery result: Success; server=ipa3.example.org, domain=example.org, kdc=ipa2.example.org,ipa3.example.org,ipa1.example.org, basedn=dc=example,dc=org
2021-02-18T04:46:20Z DEBUG Validated servers: ipa3.example.org
2021-02-18T04:46:20Z DEBUG will use discovered domain: example.org
2021-02-18T04:46:20Z DEBUG Start searching for LDAP SRV record in "example.org" (Validating DNS Discovery) and its sub-domains
2021-02-18T04:46:20Z DEBUG Search DNS for SRV record of _ldap._tcp.example.org
2021-02-18T04:46:20Z DEBUG DNS record found: 0 100 389 ipa1.example.org.
2021-02-18T04:46:20Z DEBUG DNS record found: 0 100 389 ipa2.example.org.
2021-02-18T04:46:20Z DEBUG DNS record found: 0 100 389 ipa3.example.org.
2021-02-18T04:46:20Z DEBUG DNS validated, enabling discovery
2021-02-18T04:46:20Z DEBUG will use discovered server: ipa3.example.org
2021-02-18T04:46:20Z INFO Discovery was successful!
2021-02-18T04:46:35Z DEBUG User provided NTP server(s):
2021-02-18T04:46:35Z DEBUG 10.0.40.40
2021-02-18T04:46:35Z DEBUG 10.0.40.41
2021-02-18T04:46:35Z DEBUG 10.0.40.42
2021-02-18T04:46:36Z DEBUG will use discovered realm: EXAMPLE.ORG
2021-02-18T04:46:36Z DEBUG will use discovered basedn: dc=example,dc=org
2021-02-18T04:46:36Z INFO Client hostname: gamma.example.org
2021-02-18T04:46:36Z DEBUG Hostname source: Machine's FQDN
2021-02-18T04:46:36Z INFO Realm: EXAMPLE.ORG
2021-02-18T04:46:36Z DEBUG Realm source: Discovered from LDAP DNS records in ipa3.example.org
2021-02-18T04:46:36Z INFO DNS Domain: example.org
2021-02-18T04:46:36Z DEBUG DNS Domain source: Discovered LDAP SRV records from example.org (domain of the hostname)
2021-02-18T04:46:36Z INFO IPA Server: ipa3.example.org
2021-02-18T04:46:36Z DEBUG IPA Server source: Discovered from LDAP DNS records in ipa3.example.org
2021-02-18T04:46:36Z INFO BaseDN: dc=example,dc=org
2021-02-18T04:46:36Z DEBUG BaseDN source: From IPA server ldap://ipa3.example.org:389
2021-02-18T04:46:36Z INFO NTP server: 10.0.40.40
2021-02-18T04:46:36Z INFO NTP server: 10.0.40.41
2021-02-18T04:46:36Z INFO NTP server: 10.0.40.42
2021-02-18T04:46:38Z DEBUG Loading Index file from '/var/lib/ipa-client/sysrestore/sysrestore.index'
2021-02-18T04:46:38Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:46:38Z DEBUG Starting external process
2021-02-18T04:46:38Z DEBUG args=['/usr/sbin/ipa-rmkeytab', '-k', '/etc/krb5.keytab', '-r', 'EXAMPLE.ORG']
2021-02-18T04:46:38Z DEBUG Process finished, return code=3
2021-02-18T04:46:38Z DEBUG stdout=
2021-02-18T04:46:38Z DEBUG stderr=Failed to open keytab '/etc/krb5.keytab': No such file or directory
2021-02-18T04:46:38Z DEBUG Starting external process
2021-02-18T04:46:38Z DEBUG args=['/usr/sbin/service', 'ntp', 'status', '']
2021-02-18T04:46:38Z DEBUG Process finished, return code=4
2021-02-18T04:46:38Z DEBUG stdout=
2021-02-18T04:46:38Z DEBUG stderr=Unit ntp.service could not be found.
2021-02-18T04:46:38Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:46:38Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:46:38Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:46:38Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:46:38Z INFO Synchronizing time
2021-02-18T04:46:38Z DEBUG Starting external process
2021-02-18T04:46:38Z DEBUG args=['/bin/systemctl', 'is-enabled', 'chronyd.service']
2021-02-18T04:46:38Z DEBUG Process finished, return code=0
2021-02-18T04:46:38Z DEBUG stdout=enabled
2021-02-18T04:46:38Z DEBUG stderr=
2021-02-18T04:46:38Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:46:38Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:46:38Z DEBUG Configuring chrony
2021-02-18T04:46:38Z DEBUG Setting time servers:
2021-02-18T04:46:38Z DEBUG '10.0.40.40'
2021-02-18T04:46:38Z DEBUG '10.0.40.41'
2021-02-18T04:46:38Z DEBUG '10.0.40.42'
2021-02-18T04:46:38Z DEBUG Backing up '/etc/chrony/chrony.conf'
2021-02-18T04:46:38Z DEBUG Backing up system configuration file '/etc/chrony/chrony.conf'
2021-02-18T04:46:38Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
2021-02-18T04:46:38Z DEBUG Writing configuration to '/etc/chrony/chrony.conf'
2021-02-18T04:46:38Z INFO Configuration of chrony was changed by installer.
2021-02-18T04:46:38Z DEBUG Starting external process
2021-02-18T04:46:38Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:38Z DEBUG Process execution failed
2021-02-18T04:46:38Z DEBUG Starting external process
2021-02-18T04:46:38Z DEBUG args=['/bin/systemctl', 'enable', 'chronyd.service']
2021-02-18T04:46:38Z DEBUG Process finished, return code=1
2021-02-18T04:46:38Z DEBUG stdout=
2021-02-18T04:46:38Z DEBUG stderr=Failed to enable unit: Refusing to operate on alias name or linked unit file: chronyd.service
2021-02-18T04:46:38Z DEBUG Starting external process
2021-02-18T04:46:38Z DEBUG args=['/bin/systemctl', 'restart', 'chronyd.service']
2021-02-18T04:46:39Z DEBUG Process finished, return code=0
2021-02-18T04:46:39Z DEBUG stdout=
2021-02-18T04:46:39Z DEBUG stderr=
2021-02-18T04:46:39Z DEBUG Starting external process
2021-02-18T04:46:39Z DEBUG args=['/bin/systemctl', 'is-active', 'chronyd.service']
2021-02-18T04:46:39Z DEBUG Process finished, return code=0
2021-02-18T04:46:39Z DEBUG stdout=active
2021-02-18T04:46:39Z DEBUG stderr=
2021-02-18T04:46:39Z DEBUG Restart of chronyd.service complete
2021-02-18T04:46:39Z INFO Attempting to sync time with chronyc.
2021-02-18T04:46:39Z DEBUG Starting external process
2021-02-18T04:46:39Z DEBUG args=['/usr/bin/chronyc', 'waitsync', '3', '-d']
2021-02-18T04:46:49Z DEBUG Process finished, return code=0
2021-02-18T04:46:49Z DEBUG stdout=try: 1, refid: 00000000, correction: 0.000000000, skew: 0.000
try: 2, refid: 0A002829, correction: 0.000005601, skew: 0.044
2021-02-18T04:46:49Z DEBUG stderr=
2021-02-18T04:46:49Z INFO Time synchronization was successful.
2021-02-18T04:46:51Z DEBUG will use principal provided as option: enroll-user
2021-02-18T04:46:51Z DEBUG Starting external process
2021-02-18T04:46:51Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:51Z DEBUG Process execution failed
2021-02-18T04:46:51Z DEBUG Starting external process
2021-02-18T04:46:51Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0']
2021-02-18T04:46:51Z DEBUG Process finished, return code=0
2021-02-18T04:46:51Z DEBUG stdout=54021793
2021-02-18T04:46:51Z DEBUG stderr=
2021-02-18T04:46:51Z DEBUG Enabling persistent keyring CCACHE
2021-02-18T04:46:51Z DEBUG Writing Kerberos configuration to /tmp/tmpddbc3x8t:
2021-02-18T04:46:51Z DEBUG #File modified by ipa-client-install
includedir /etc/krb5.conf.d/
includedir /var/lib/sss/pubconf/krb5.include.d/
[libdefaults]
default_realm = EXAMPLE.ORG
dns_lookup_realm = false
dns_lookup_kdc = false
rdns = false
dns_canonicalize_hostname = false
ticket_lifetime = 24h
forwardable = true
udp_preference_limit = 0
default_ccache_name = KEYRING:persistent:%{uid}
[realms]
EXAMPLE.ORG = {
kdc = ipa3.example.org:88
master_kdc = ipa3.example.org:88
admin_server = ipa3.example.org:749
kpasswd_server = ipa3.example.org:464
default_domain = example.org
pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem
pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem
}
[domain_realm]
.example.org = EXAMPLE.ORG
example.org = EXAMPLE.ORG
gamma.example.org = EXAMPLE.ORG
2021-02-18T04:46:51Z DEBUG Writing configuration file /tmp/tmpddbc3x8t
2021-02-18T04:46:51Z DEBUG #File modified by ipa-client-install
includedir /etc/krb5.conf.d/
includedir /var/lib/sss/pubconf/krb5.include.d/
[libdefaults]
default_realm = EXAMPLE.ORG
dns_lookup_realm = false
dns_lookup_kdc = false
rdns = false
dns_canonicalize_hostname = false
ticket_lifetime = 24h
forwardable = true
udp_preference_limit = 0
default_ccache_name = KEYRING:persistent:%{uid}
[realms]
EXAMPLE.ORG = {
kdc = ipa3.example.org:88
master_kdc = ipa3.example.org:88
admin_server = ipa3.example.org:749
kpasswd_server = ipa3.example.org:464
default_domain = example.org
pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem
pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem
}
[domain_realm]
.example.org = EXAMPLE.ORG
example.org = EXAMPLE.ORG
gamma.example.org = EXAMPLE.ORG
2021-02-18T04:46:58Z DEBUG Initializing principal enroll-user@EXAMPLE.ORG using password
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/bin/kinit', 'enroll-user@EXAMPLE.ORG', '-c', '/tmp/krbccup79sb0l/ccache']
2021-02-18T04:46:58Z DEBUG Process finished, return code=0
2021-02-18T04:46:58Z DEBUG stdout=Password for enroll-user@EXAMPLE.ORG:
2021-02-18T04:46:58Z DEBUG stderr=
2021-02-18T04:46:58Z DEBUG trying to retrieve CA cert via LDAP from ipa3.example.org
2021-02-18T04:46:58Z DEBUG retrieving schema for SchemaCache url=ldap://ipa3.example.org:389 conn=<ldap.ldapobject.SimpleLDAPObject object at 0x7f7f2d3462b0>
2021-02-18T04:46:58Z INFO Successfully retrieved CA cert
Subject: CN=Example-Org Internal Root CA,O=EXAMPLE.ORG
Issuer: CN=Example-Org Internal Root CA,O=EXAMPLE.ORG
Valid From: 2021-01-12 21:01:48
Valid Until: 2041-01-12 21:01:48
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/sbin/ipa-join', '-s', 'ipa3.example.org', '-b', 'dc=example,dc=org', '-h', 'gamma.example.org']
2021-02-18T04:46:58Z DEBUG Process finished, return code=0
2021-02-18T04:46:58Z DEBUG stdout=
2021-02-18T04:46:58Z DEBUG stderr=Keytab successfully retrieved and stored in: /etc/krb5.keytab
2021-02-18T04:46:58Z INFO Enrolled in IPA realm EXAMPLE.ORG
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/bin/kdestroy']
2021-02-18T04:46:58Z DEBUG Process finished, return code=0
2021-02-18T04:46:58Z DEBUG stdout=
2021-02-18T04:46:58Z DEBUG stderr=
2021-02-18T04:46:58Z DEBUG Initializing principal host/gamma.example.org@EXAMPLE.ORG using keytab /etc/krb5.keytab
2021-02-18T04:46:58Z DEBUG using ccache /etc/ipa/.dns_ccache
2021-02-18T04:46:58Z DEBUG Attempt 1/5: success
2021-02-18T04:46:58Z DEBUG Backing up system configuration file '/etc/ipa/default.conf'
2021-02-18T04:46:58Z DEBUG -> Not backing up - '/etc/ipa/default.conf' doesn't exist
2021-02-18T04:46:58Z DEBUG Writing configuration file /etc/ipa/default.conf
2021-02-18T04:46:58Z DEBUG #File modified by ipa-client-install
[global]
basedn = dc=example,dc=org
realm = EXAMPLE.ORG
domain = example.org
server = ipa3.example.org
host = gamma.example.org
xmlrpc_uri = https://ipa3.example.org/ipa/xml
enable_ra = True
2021-02-18T04:46:58Z INFO Created /etc/ipa/default.conf
2021-02-18T04:46:58Z DEBUG Backing up system configuration file '/etc/sssd/sssd.conf'
2021-02-18T04:46:58Z DEBUG -> Not backing up - '/etc/sssd/sssd.conf' doesn't exist
2021-02-18T04:46:58Z DEBUG New SSSD config will be created
2021-02-18T04:46:58Z DEBUG Backing up system configuration file '/etc/nsswitch.conf'
2021-02-18T04:46:58Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
2021-02-18T04:46:58Z DEBUG Updating configuration file /etc/nsswitch.conf
2021-02-18T04:46:58Z DEBUG
# /etc/nsswitch.conf
#
# Example configuration of GNU Name Service Switch functionality.
# If you have the `glibc-doc-reference' and `info' packages installed, try:
# `info libc "Name Service Switch"' for information about this file.
passwd: files systemd
group: files systemd
shadow: files
gshadow: files
hosts: files dns
networks: files
protocols: db files
services: db files
ethers: db files
rpc: db files
netgroup: nis
sudoers: files sss
2021-02-18T04:46:58Z INFO Configured sudoers in /etc/nsswitch.conf
2021-02-18T04:46:58Z INFO Configured /etc/sssd/sssd.conf
2021-02-18T04:46:58Z DEBUG Backing up system configuration file '/etc/krb5.conf'
2021-02-18T04:46:58Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:58Z DEBUG Process execution failed
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/bin/keyctl', 'get_persistent', '@s', '0']
2021-02-18T04:46:58Z DEBUG Process finished, return code=0
2021-02-18T04:46:58Z DEBUG stdout=54021793
2021-02-18T04:46:58Z DEBUG stderr=
2021-02-18T04:46:58Z DEBUG Enabling persistent keyring CCACHE
2021-02-18T04:46:58Z DEBUG Writing Kerberos configuration to /etc/krb5.conf:
2021-02-18T04:46:58Z DEBUG #File modified by ipa-client-install
includedir /etc/krb5.conf.d/
includedir /var/lib/sss/pubconf/krb5.include.d/
[libdefaults]
default_realm = EXAMPLE.ORG
dns_lookup_realm = true
dns_lookup_kdc = true
rdns = false
dns_canonicalize_hostname = false
ticket_lifetime = 24h
forwardable = true
udp_preference_limit = 0
default_ccache_name = KEYRING:persistent:%{uid}
[realms]
EXAMPLE.ORG = {
pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem
pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem
}
[domain_realm]
.example.org = EXAMPLE.ORG
example.org = EXAMPLE.ORG
gamma.example.org = EXAMPLE.ORG
2021-02-18T04:46:58Z DEBUG Writing configuration file /etc/krb5.conf
2021-02-18T04:46:58Z DEBUG #File modified by ipa-client-install
includedir /etc/krb5.conf.d/
includedir /var/lib/sss/pubconf/krb5.include.d/
[libdefaults]
default_realm = EXAMPLE.ORG
dns_lookup_realm = true
dns_lookup_kdc = true
rdns = false
dns_canonicalize_hostname = false
ticket_lifetime = 24h
forwardable = true
udp_preference_limit = 0
default_ccache_name = KEYRING:persistent:%{uid}
[realms]
EXAMPLE.ORG = {
pkinit_anchors = FILE:/var/lib/ipa-client/pki/kdc-ca-bundle.pem
pkinit_pool = FILE:/var/lib/ipa-client/pki/ca-bundle.pem
}
[domain_realm]
.example.org = EXAMPLE.ORG
example.org = EXAMPLE.ORG
gamma.example.org = EXAMPLE.ORG
2021-02-18T04:46:58Z INFO Configured /etc/krb5.conf for IPA realm EXAMPLE.ORG
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/bin/certutil', '-d', '/tmp/tmp91_4bnnm', '-N', '-f', '/tmp/tmp91_4bnnm/pwdfile.txt', '-@', '/tmp/tmp91_4bnnm/pwdfile.txt']
2021-02-18T04:46:58Z DEBUG Process finished, return code=0
2021-02-18T04:46:58Z DEBUG stdout=
2021-02-18T04:46:58Z DEBUG stderr=
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:58Z DEBUG Process execution failed
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:58Z DEBUG Process execution failed
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:58Z DEBUG Process execution failed
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:58Z DEBUG Process execution failed
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:58Z DEBUG Process execution failed
2021-02-18T04:46:58Z DEBUG Starting external process
2021-02-18T04:46:58Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/tmp/tmp91_4bnnm', '-A', '-n', 'CA certificate 1', '-t', 'C,,', '-a', '-f', '/tmp/tmp91_4bnnm/pwdfile.txt']
2021-02-18T04:46:58Z DEBUG Process finished, return code=0
2021-02-18T04:46:58Z DEBUG stdout=
2021-02-18T04:46:58Z DEBUG stderr=
2021-02-18T04:46:58Z DEBUG importing all plugin modules in ipaclient.remote_plugins.schema$70235405...
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.remote_plugins.schema$70235405.plugins
2021-02-18T04:46:58Z DEBUG importing all plugin modules in ipaclient.plugins...
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.automember
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.automount
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.ca
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.cert
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.certmap
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.certprofile
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.csrgen
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.dns
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.hbacrule
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.hbactest
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.host
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.idrange
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.internal
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.location
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.migration
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.misc
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.otptoken
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.otptoken_yubikey
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.passwd
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.permission
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.rpcclient
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.server
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.service
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.sudorule
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.topology
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.trust
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.user
2021-02-18T04:46:58Z DEBUG importing plugin module ipaclient.plugins.vault
2021-02-18T04:46:59Z DEBUG failed to find session_cookie in persistent storage for principal 'host/gamma.example.org@EXAMPLE.ORG'
2021-02-18T04:46:59Z DEBUG trying https://ipa3.example.org/ipa/json
2021-02-18T04:46:59Z DEBUG New HTTP connection (ipa3.example.org)
2021-02-18T04:46:59Z DEBUG received Set-Cookie (<class 'list'>)'['ipa_session=MagBearerToken=vxYfKV77dK62RzVQVoKRP1viq7XuDyIjkOijYCod1O%2bf2bK9W5IsuKSIo4IJJvCyMCFoi8touBDCQGK7BrslkQQCdRBK7NwUcaCUswkskRB0gYc%2fXXLdHFTiE9XbnsYaWBpYj5m2xnNefkg9wmIukPb3xwnxYzw3%2bTjTnU7wDv68EwdmCuyUfKe5LBjoBGdGevJBgSTwiu%2fbgSQiJBgWPfSZYWzRE8OYiFuSvSvFeJ7db0ixFH1z%2bzlMSQCtxxtyIr9YYb6pLjW2xw6dyvWoqhtyIWBP1ZhnL8w66vK%2flGI%3d;path=/ipa;httponly;secure;']'
2021-02-18T04:46:59Z DEBUG storing cookie 'ipa_session=MagBearerToken=vxYfKV77dK62RzVQVoKRP1viq7XuDyIjkOijYCod1O%2bf2bK9W5IsuKSIo4IJJvCyMCFoi8touBDCQGK7BrslkQQCdRBK7NwUcaCUswkskRB0gYc%2fXXLdHFTiE9XbnsYaWBpYj5m2xnNefkg9wmIukPb3xwnxYzw3%2bTjTnU7wDv68EwdmCuyUfKe5LBjoBGdGevJBgSTwiu%2fbgSQiJBgWPfSZYWzRE8OYiFuSvSvFeJ7db0ixFH1z%2bzlMSQCtxxtyIr9YYb6pLjW2xw6dyvWoqhtyIWBP1ZhnL8w66vK%2flGI%3d;' for principal host/gamma.example.org@EXAMPLE.ORG
2021-02-18T04:46:59Z DEBUG Created connection context.rpcclient_140184180230560
2021-02-18T04:46:59Z DEBUG Try RPC connection
2021-02-18T04:46:59Z DEBUG [try 1]: Forwarding 'ping' to json server 'https://ipa3.example.org/ipa/json'
2021-02-18T04:46:59Z DEBUG HTTP connection keep-alive (ipa3.example.org)
2021-02-18T04:46:59Z DEBUG received Set-Cookie (<class 'list'>)'['ipa_session=MagBearerToken=68V%2fySEpGRp7b%2bQX%2fXeZiar90opBBrqlazPc3YQ%2fGAzyEuTUlL8jsTivB5fhZOTAaRbjd%2fNBLsuQPnR4d99XYGXUvjMmM3nGTjDgCr10%2b4MnnrryJ2BlU0K98GtVyM2akGLBdtcAib0zNGqtrgMOe72BF5SED2hrxrWgg%2fxYDgdwG2tdIYyFQ8a%2fuBmO6Ip6yzj02doR5iDaDqnl1GjdJ3qgmwyGN7pmPZRn0cqwVtoxsTAvba52Ttu43JmS0GT4h%2fasSdZA8N3Wv4XdVX7u%2bcIwZ2x6Ru0u74lXpPzIu34%3d;path=/ipa;httponly;secure;']'
2021-02-18T04:46:59Z DEBUG storing cookie 'ipa_session=MagBearerToken=68V%2fySEpGRp7b%2bQX%2fXeZiar90opBBrqlazPc3YQ%2fGAzyEuTUlL8jsTivB5fhZOTAaRbjd%2fNBLsuQPnR4d99XYGXUvjMmM3nGTjDgCr10%2b4MnnrryJ2BlU0K98GtVyM2akGLBdtcAib0zNGqtrgMOe72BF5SED2hrxrWgg%2fxYDgdwG2tdIYyFQ8a%2fuBmO6Ip6yzj02doR5iDaDqnl1GjdJ3qgmwyGN7pmPZRn0cqwVtoxsTAvba52Ttu43JmS0GT4h%2fasSdZA8N3Wv4XdVX7u%2bcIwZ2x6Ru0u74lXpPzIu34%3d;' for principal host/gamma.example.org@EXAMPLE.ORG
2021-02-18T04:46:59Z DEBUG [try 1]: Forwarding 'ca_is_enabled' to json server 'https://ipa3.example.org/ipa/json'
2021-02-18T04:46:59Z DEBUG HTTP connection keep-alive (ipa3.example.org)
2021-02-18T04:46:59Z DEBUG received Set-Cookie (<class 'list'>)'['ipa_session=MagBearerToken=dJiaX3PGvdydbHYEMShWbFmCvBMJ1uGwVqmv13NO1oQEivzilIJx4FvmsSPiJULUx0PwFeXJSI0%2ftitVzH3G9Vx0S0W3q1M5oxyJeoSWtkxRWP7NQ1eHcfON3oQEwPV6lal7tgKNrb4SiVQNWtbiK5DOuZdGPwrb1fDarA80ozvNdmBZOkQp2lQSUkOOpQWUgvMisJ5f7NFxtkX%2bmAQ58xC4tP3f%2bS7%2beOXVl7p0f0CBkOj7gF791wHzEFmHIhdYuyqBTRrVGjrUsDU1UHTJDXvP92KmmmwDhbDtALkgekc%3d;path=/ipa;httponly;secure;']'
2021-02-18T04:46:59Z DEBUG storing cookie 'ipa_session=MagBearerToken=dJiaX3PGvdydbHYEMShWbFmCvBMJ1uGwVqmv13NO1oQEivzilIJx4FvmsSPiJULUx0PwFeXJSI0%2ftitVzH3G9Vx0S0W3q1M5oxyJeoSWtkxRWP7NQ1eHcfON3oQEwPV6lal7tgKNrb4SiVQNWtbiK5DOuZdGPwrb1fDarA80ozvNdmBZOkQp2lQSUkOOpQWUgvMisJ5f7NFxtkX%2bmAQ58xC4tP3f%2bS7%2beOXVl7p0f0CBkOj7gF791wHzEFmHIhdYuyqBTRrVGjrUsDU1UHTJDXvP92KmmmwDhbDtALkgekc%3d;' for principal host/gamma.example.org@EXAMPLE.ORG
2021-02-18T04:46:59Z DEBUG [try 1]: Forwarding 'config_show' to json server 'https://ipa3.example.org/ipa/json'
2021-02-18T04:46:59Z DEBUG HTTP connection keep-alive (ipa3.example.org)
2021-02-18T04:46:59Z DEBUG received Set-Cookie (<class 'list'>)'['ipa_session=MagBearerToken=KCtx54KoSVTyY7KGbuSpNI4fSB4VtZxlKBq2oOoFDAjslMvofxa1m4Oxk9Fkb2J5XZvHCzdgXh%2btbZmmArNGtG6XwamTo1D3XLAzqsW5XRpG8hXBxGU3C6fPOwCyAyRDJE%2fyTe4frG81ekF5DErhiCJorr9nEE3NJPXxPaBGOIL7NoYm1bH8X4Q0VqIrTJJZMwrHKD%2bYGtEp3ldfJ0Mx%2fLTr7n0uAa03rLNfOOTTgqEhK1EP8V9yHBcXhXWxuDjVn53%2bhKL1btyHn5yo6ik%2b37Lpftmorei1ZufkOpbMlVw%3d;path=/ipa;httponly;secure;']'
2021-02-18T04:46:59Z DEBUG storing cookie 'ipa_session=MagBearerToken=KCtx54KoSVTyY7KGbuSpNI4fSB4VtZxlKBq2oOoFDAjslMvofxa1m4Oxk9Fkb2J5XZvHCzdgXh%2btbZmmArNGtG6XwamTo1D3XLAzqsW5XRpG8hXBxGU3C6fPOwCyAyRDJE%2fyTe4frG81ekF5DErhiCJorr9nEE3NJPXxPaBGOIL7NoYm1bH8X4Q0VqIrTJJZMwrHKD%2bYGtEp3ldfJ0Mx%2fLTr7n0uAa03rLNfOOTTgqEhK1EP8V9yHBcXhXWxuDjVn53%2bhKL1btyHn5yo6ik%2b37Lpftmorei1ZufkOpbMlVw%3d;' for principal host/gamma.example.org@EXAMPLE.ORG
2021-02-18T04:46:59Z DEBUG Starting external process
2021-02-18T04:46:59Z DEBUG args=['/usr/bin/certutil', '-d', '/etc/ipa/nssdb', '-N', '-f', '/etc/ipa/nssdb/pwdfile.txt', '-@', '/etc/ipa/nssdb/pwdfile.txt']
2021-02-18T04:46:59Z DEBUG Process finished, return code=0
2021-02-18T04:46:59Z DEBUG stdout=
2021-02-18T04:46:59Z DEBUG stderr=
2021-02-18T04:46:59Z DEBUG Starting external process
2021-02-18T04:46:59Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:59Z DEBUG Process execution failed
2021-02-18T04:46:59Z DEBUG Starting external process
2021-02-18T04:46:59Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:59Z DEBUG Process execution failed
2021-02-18T04:46:59Z DEBUG Starting external process
2021-02-18T04:46:59Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:59Z DEBUG Process execution failed
2021-02-18T04:46:59Z DEBUG Starting external process
2021-02-18T04:46:59Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:59Z DEBUG Process execution failed
2021-02-18T04:46:59Z DEBUG Starting external process
2021-02-18T04:46:59Z DEBUG args=['/usr/sbin/selinuxenabled']
2021-02-18T04:46:59Z DEBUG Process execution failed
2021-02-18T04:46:59Z DEBUG Adding CA certificates to the IPA NSS database.
2021-02-18T04:46:59Z DEBUG Starting external process
2021-02-18T04:46:59Z DEBUG args=['/usr/bin/certutil', '-d', 'sql:/etc/ipa/nssdb', '-A', '-n', 'EXAMPLE.ORG IPA CA', '-t', 'CT,C,C', '-a', '-f', '/etc/ipa/nssdb/pwdfile.txt']
2021-02-18T04:46:59Z DEBUG Process finished, return code=0
2021-02-18T04:46:59Z DEBUG stdout=
2021-02-18T04:46:59Z DEBUG stderr=
2021-02-18T04:46:59Z DEBUG Starting external process
2021-02-18T04:46:59Z DEBUG args=['/usr/sbin/update-ca-certificates']
2021-02-18T04:47:00Z DEBUG Process finished, return code=0
2021-02-18T04:47:00Z DEBUG stdout=Updating certificates in /etc/ssl/certs...
0 added, 0 removed; done.
Running hooks in /etc/ca-certificates/update.d...
done.
2021-02-18T04:47:00Z DEBUG stderr=
2021-02-18T04:47:00Z INFO Systemwide CA database updated.
2021-02-18T04:47:00Z DEBUG found 1 A records for gamma.example.org.: 10.0.40.61
2021-02-18T04:47:00Z DEBUG The DNS response does not contain an answer to the question: gamma.example.org. IN AAAA
2021-02-18T04:47:00Z DEBUG Starting external process
2021-02-18T04:47:00Z DEBUG args=['/bin/systemctl', 'try-restart', 'certmonger.service']
2021-02-18T04:47:00Z DEBUG Process finished, return code=0
2021-02-18T04:47:00Z DEBUG stdout=
2021-02-18T04:47:00Z DEBUG stderr=
2021-02-18T04:47:00Z DEBUG Starting external process
2021-02-18T04:47:00Z DEBUG args=['/bin/systemctl', 'is-active', 'certmonger.service']
2021-02-18T04:47:00Z DEBUG Process finished, return code=3
2021-02-18T04:47:00Z DEBUG stdout=inactive
2021-02-18T04:47:00Z DEBUG stderr=
2021-02-18T04:47:00Z DEBUG Restart of certmonger.service complete
2021-02-18T04:47:00Z INFO Adding SSH public key from /etc/ssh/ssh_host_ecdsa_key.pub
2021-02-18T04:47:00Z INFO Adding SSH public key from /etc/ssh/ssh_host_rsa_key.pub
2021-02-18T04:47:00Z INFO Adding SSH public key from /etc/ssh/ssh_host_ed25519_key.pub
2021-02-18T04:47:00Z INFO Adding SSH public key from /etc/ssh/ssh_host_dsa_key.pub
2021-02-18T04:47:00Z DEBUG [try 1]: Forwarding 'host_mod' to json server 'https://ipa3.example.org/ipa/json'
2021-02-18T04:47:00Z DEBUG HTTP connection keep-alive (ipa3.example.org)
2021-02-18T04:47:00Z DEBUG received Set-Cookie (<class 'list'>)'['ipa_session=MagBearerToken=%2fTZjrQKH1jjm8SMLN6Xo9wFr2%2fmMTDsmSh3C8lix1UPcrZMFgK4PRZrAxYTxlW2LSqVWaYfjlqoRDu3T%2beJOhT8fNeFpG%2bx5Is2VAnVJul6uO2QIC2nJDhhn475wN57FWN7FGN2hJfZ7tYUfL1J6WWh9YcJNfuSTv8notwKV35%2b4gyjdO7vsbYx0HYdKjFbulVHV7gI6zV1TUdJUx7gG0UYtAKCTRN2wDiIdhyf7jybKegbRRq9d8u7%2f9XLFqyzW2FGRFOT%2bWrH0qHGOJIEHEardYEPbyA702u6vEyU4pyQ%3d;path=/ipa;httponly;secure;']'
2021-02-18T04:47:00Z DEBUG storing cookie 'ipa_session=MagBearerToken=%2fTZjrQKH1jjm8SMLN6Xo9wFr2%2fmMTDsmSh3C8lix1UPcrZMFgK4PRZrAxYTxlW2LSqVWaYfjlqoRDu3T%2beJOhT8fNeFpG%2bx5Is2VAnVJul6uO2QIC2nJDhhn475wN57FWN7FGN2hJfZ7tYUfL1J6WWh9YcJNfuSTv8notwKV35%2b4gyjdO7vsbYx0HYdKjFbulVHV7gI6zV1TUdJUx7gG0UYtAKCTRN2wDiIdhyf7jybKegbRRq9d8u7%2f9XLFqyzW2FGRFOT%2bWrH0qHGOJIEHEardYEPbyA702u6vEyU4pyQ%3d;' for principal host/gamma.example.org@EXAMPLE.ORG
2021-02-18T04:47:00Z DEBUG Writing nsupdate commands to /etc/ipa/.dns_update.txt:
2021-02-18T04:47:00Z DEBUG debug
update delete gamma.example.org. IN SSHFP
show
send
update add gamma.example.org. 1200 IN SSHFP 3 1 BCA7405C01C606CFA1BA37EDBF5F70A91BB3E4BD
update add gamma.example.org. 1200 IN SSHFP 3 2 BFB21B2C1654AC35B9E3CB2C1046D619086E2397C01800711814A421F1475589
update add gamma.example.org. 1200 IN SSHFP 1 1 99624B09B1C873E165F8C38FB0A0BF56D80A0640
update add gamma.example.org. 1200 IN SSHFP 1 2 91984447E685EABA8A39B02822EBAF213462D0F293A685CF443641EDFEE8B47B
update add gamma.example.org. 1200 IN SSHFP 4 1 184DB53BC80F2FBEFEEA02E1E19AD2F2AF5D8FCC
update add gamma.example.org. 1200 IN SSHFP 4 2 F282B6F8992CA1D904A5A9AA08A95E43A01AC82A846E06CD5C46C73A91591234
update add gamma.example.org. 1200 IN SSHFP 2 1 32241FEC8CCE30791EF7AF3AA2E8DFFEC03FF340
update add gamma.example.org. 1200 IN SSHFP 2 2 6F57C5C5E2BAE28570913B3846189621B929F62DD7000EB8EF7858FCA544F892
show
send
2021-02-18T04:47:00Z DEBUG Starting external process
2021-02-18T04:47:00Z DEBUG args=['/usr/bin/nsupdate', '-g', '/etc/ipa/.dns_update.txt']
2021-02-18T04:47:00Z DEBUG Process finished, return code=0
2021-02-18T04:47:00Z DEBUG stdout=Outgoing update query:
;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0
;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
gamma.example.org. 0 ANY SSHFP
Outgoing update query:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46046
;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
;; QUESTION SECTION:
;2250994423.sig-ipa1.example.org. ANY TKEY
;; ADDITIONAL SECTION:
2250994423.sig-ipa1.example.org. 0 ANY TKEY gss-tsig. 1613623620 1613623620 3 NOERROR 702 YIICugYGKwYBBQUCoIICrjCCAqqgDTALBgkqhkiG9xIBAgKiggKXBIIC k2CCAo8GCSqGSIb3EgECAgEAboICfjCCAnqgAwIBBaEDAgEOogcDBQAg AAAAo4IBeGGCAXQwggFwoAMCAQWhEBsORU1QT1dFUkNMRS5ORVSiJTAj oAMCAQGhHDAaGwNETlMbE2lwYTEuZW1wb3dlcmNsZS5uZXSjggEuMIIB KqADAgESoQMCAQKiggEcBIIBGMCOt96m+aqsH3MniWmPOf62WlHVDnla m0ePQvZXAPwJWEE5U1V5mRu8vwe+f31xuej1x3ymNVJcNgJvYzhz+H4J Z3+Vy/AjHlxIgNks6s40sH8zfu5csDXY77vubAWUkKQG96cmTfuOFyEK 7xGF5SeN+TztMJV7sBD7yluaStunTdmASY+SKlV6pucmjA6AB/9vAihC IuHsNKpjk2IiqMB5FaiIxDSBtnJasYJq4B59QI0WP2xoBTEWGmLGnrs9 rBGs1hI8czIdh5ioGBiA+iunfW3kYXHZS6tDP/oUYVP1teYNB5eOhwKk Js+ijOzjVopZXCijQeFClCava+H/+2gyQCRZ4jvCRIyfnhyGvGP8P6rC mLMQspOkgegwgeWgAwIBEqKB3QSB2kndGApAxpIH8+gia+cWuBtFL1wp b9Rfr+i5UTBzdO+ybnce+EWBl9Y9QYRVenoTQEFN/jLM/Dlp1aR6oLAW Cy8CmlM7TjvYfh4zmiRfWIbc9DViN4JF+Sd9imTxQtOtiP0RVurgUnQ/ Ob2F0Byn0y2qlSfBKADT8dtWOfnSWphC7H4HPiXVVjLrj8ek0XmfN3sE WOfYUltWW/+OtEmsYRfZQRu+t0gJJtWwHEsaOEV+goZ9ykqnMo22uQw2 MHrQ6hXDj6y2p4rIUlwmW4mmqbvcUjKiNc4KmCPr 0
Outgoing update query:
;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 6778
;; flags:; ZONE: 1, PREREQ: 0, UPDATE: 1, ADDITIONAL: 1
;; UPDATE SECTION:
gamma.example.org. 0 ANY SSHFP
;; TSIG PSEUDOSECTION:
2250994423.sig-ipa1.example.org. 0 ANY TSIG gss-tsig. 1613623620 300 28 BAQE//////8AAAAAK4Mb9P3oBCDaxwj5XtkdwA== 6778 NOERROR 0
Outgoing update query:
;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 0
;; flags:; ZONE: 0, PREREQ: 0, UPDATE: 0, ADDITIONAL: 0
;; UPDATE SECTION:
gamma.example.org. 1200 IN SSHFP 3 1 BCA7405C01C606CFA1BA37EDBF5F70A91BB3E4BD
gamma.example.org. 1200 IN SSHFP 3 2 BFB21B2C1654AC35B9E3CB2C1046D619086E2397C01800711814A421 F1475589
gamma.example.org. 1200 IN SSHFP 1 1 99624B09B1C873E165F8C38FB0A0BF56D80A0640
gamma.example.org. 1200 IN SSHFP 1 2 91984447E685EABA8A39B02822EBAF213462D0F293A685CF443641ED FEE8B47B
gamma.example.org. 1200 IN SSHFP 4 1 184DB53BC80F2FBEFEEA02E1E19AD2F2AF5D8FCC
gamma.example.org. 1200 IN SSHFP 4 2 F282B6F8992CA1D904A5A9AA08A95E43A01AC82A846E06CD5C46C73A 91591234
gamma.example.org. 1200 IN SSHFP 2 1 32241FEC8CCE30791EF7AF3AA2E8DFFEC03FF340
gamma.example.org. 1200 IN SSHFP 2 2 6F57C5C5E2BAE28570913B3846189621B929F62DD7000EB8EF7858FC A544F892
Outgoing update query:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 45099
;; flags:; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
;; QUESTION SECTION:
;3634389539.sig-ipa1.example.org. ANY TKEY
;; ADDITIONAL SECTION:
3634389539.sig-ipa1.example.org. 0 ANY TKEY gss-tsig. 1613623620 1613623620 3 NOERROR 702 YIICugYGKwYBBQUCoIICrjCCAqqgDTALBgkqhkiG9xIBAgKiggKXBIIC k2CCAo8GCSqGSIb3EgECAgEAboICfjCCAnqgAwIBBaEDAgEOogcDBQAg AAAAo4IBeGGCAXQwggFwoAMCAQWhEBsORU1QT1dFUkNMRS5ORVSiJTAj oAMCAQGhHDAaGwNETlMbE2lwYTEuZW1wb3dlcmNsZS5uZXSjggEuMIIB KqADAgESoQMCAQKiggEcBIIBGMCOt96m+aqsH3MniWmPOf62WlHVDnla m0ePQvZXAPwJWEE5U1V5mRu8vwe+f31xuej1x3ymNVJcNgJvYzhz+H4J Z3+Vy/AjHlxIgNks6s40sH8zfu5csDXY77vubAWUkKQG96cmTfuOFyEK 7xGF5SeN+TztMJV7sBD7yluaStunTdmASY+SKlV6pucmjA6AB/9vAihC IuHsNKpjk2IiqMB5FaiIxDSBtnJasYJq4B59QI0WP2xoBTEWGmLGnrs9 rBGs1hI8czIdh5ioGBiA+iunfW3kYXHZS6tDP/oUYVP1teYNB5eOhwKk Js+ijOzjVopZXCijQeFClCava+H/+2gyQCRZ4jvCRIyfnhyGvGP8P6rC mLMQspOkgegwgeWgAwIBEqKB3QSB2sEQFWLsGB3kYVuMlJ+al6Z8RjHX yfSJBclVPqmdFkuDBpIjdRtEpewfxBMSK8ygLXOBRMu/xhgTunL4JGGw eMfcvlEqdhwirg8+sOHifRUhFIHMLauSR6KE1q0zqosPylr+25qs9gk/ B1mT6rnYQFwuff0DZbZFX/VuQyE+texky+S6znFZl2qsxlDfjTPAuj0z YwUfyyO69h+/ZkuSH6Jh5Sc3nPmdjI4i1NQVQNGt1DwkyMfVt4LWbObt KF4LbEaUHUXqnmiqk8wPDiAZf2QAr012zn5lEqbk 0
Outgoing update query:
;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 30659
;; flags:; ZONE: 1, PREREQ: 0, UPDATE: 8, ADDITIONAL: 1
;; UPDATE SECTION:
gamma.example.org. 1200 IN SSHFP 3 1 BCA7405C01C606CFA1BA37EDBF5F70A91BB3E4BD
gamma.example.org. 1200 IN SSHFP 3 2 BFB21B2C1654AC35B9E3CB2C1046D619086E2397C01800711814A421 F1475589
gamma.example.org. 1200 IN SSHFP 1 1 99624B09B1C873E165F8C38FB0A0BF56D80A0640
gamma.example.org. 1200 IN SSHFP 1 2 91984447E685EABA8A39B02822EBAF213462D0F293A685CF443641ED FEE8B47B
gamma.example.org. 1200 IN SSHFP 4 1 184DB53BC80F2FBEFEEA02E1E19AD2F2AF5D8FCC
gamma.example.org. 1200 IN SSHFP 4 2 F282B6F8992CA1D904A5A9AA08A95E43A01AC82A846E06CD5C46C73A 91591234
gamma.example.org. 1200 IN SSHFP 2 1 32241FEC8CCE30791EF7AF3AA2E8DFFEC03FF340
gamma.example.org. 1200 IN SSHFP 2 2 6F57C5C5E2BAE28570913B3846189621B929F62DD7000EB8EF7858FC A544F892
;; TSIG PSEUDOSECTION:
3634389539.sig-ipa1.example.org. 0 ANY TSIG gss-tsig. 1613623620 300 28 BAQE//////8AAAAAEJnK5HvP3ulxMUNfFzbhVg== 30659 NOERROR 0
2021-02-18T04:47:00Z DEBUG stderr=Reply from SOA query:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 16466
;; flags: qr rd ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;gamma.example.org. IN SOA
Reply from SOA query:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 37740
;; flags: qr rd ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;example.org. IN SOA
;; ANSWER SECTION:
example.org. 2432 IN SOA ipa1.example.org. hostmaster.example.org. 1613609672 3600 900 1209600 3600
Found zone name: example.org
The master is: ipa1.example.org
start_gssrequest
Found realm from ticket: EXAMPLE.ORG
send_gssrequest
recvmsg reply from GSS-TSIG query
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46046
;; flags: qr ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;2250994423.sig-ipa1.example.org. ANY TKEY
;; ANSWER SECTION:
2250994423.sig-ipa1.example.org. 0 ANY TKEY gss-tsig. 1613623620 1613627220 3 NOERROR 186 oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIB AgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvEsfKOIiS3d3A 8zcoBG8ybO7XCmLMYR49kte0wtyEwaJ9h4H0wcsJik3J2CkUvaLI1xLA Bb0jlfJfXJil0C8MdNe7nDsa3saqSSQZ5zmsLsxg7+ejO9l6ThXsDa+T d8zWkM7TAf0E3+QhZ8+eknjm 0
Sending update to 10.0.40.40#53
Reply from update query:
;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 6778
;; flags: qr; ZONE: 1, PREREQ: 0, UPDATE: 0, ADDITIONAL: 1
;; ZONE SECTION:
;example.org. IN SOA
;; TSIG PSEUDOSECTION:
2250994423.sig-ipa1.example.org. 0 ANY TSIG gss-tsig. 1613623620 300 28 BAQF//////8AAAAAGBkocQf5mr0EzFlVn8B8uQ== 6778 NOERROR 0
Reply from SOA query:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25044
;; flags: qr rd ra; QUESTION: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;gamma.example.org. IN SOA
Reply from SOA query:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 33478
;; flags: qr rd ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;example.org. IN SOA
;; ANSWER SECTION:
example.org. 2432 IN SOA ipa1.example.org. hostmaster.example.org. 1613609672 3600 900 1209600 3600
Found zone name: example.org
The master is: ipa1.example.org
start_gssrequest
send_gssrequest
recvmsg reply from GSS-TSIG query
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 45099
;; flags: qr ra; QUESTION: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;3634389539.sig-ipa1.example.org. ANY TKEY
;; ANSWER SECTION:
3634389539.sig-ipa1.example.org. 0 ANY TKEY gss-tsig. 1613623620 1613627220 3 NOERROR 186 oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIB AgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRv02kKpo3el7EN KtbiHMnTpMc7RA/ShR2IaMnUKc6IWN/SK1xsUh1oZ38mY805fME98jgd NHSaaippS5n307R0A/kflGC9m8gqWyWnuujoxekOcExYUpeQi4GNxb39 RlTzx5G6SwHCogO/gjm3eqxD 0
Sending update to 10.0.40.40#53
Reply from update query:
;; ->>HEADER<<- opcode: UPDATE, status: NOERROR, id: 30659
;; flags: qr; ZONE: 1, PREREQ: 0, UPDATE: 0, ADDITIONAL: 1
;; ZONE SECTION:
;example.org. IN SOA
;; TSIG PSEUDOSECTION:
3634389539.sig-ipa1.example.org. 0 ANY TSIG gss-tsig. 1613623620 300 28 BAQF//////8AAAAAEQj4PfOeoeWnW+TNJt0HWQ== 30659 NOERROR 0
2021-02-18T04:47:00Z DEBUG Starting external process
2021-02-18T04:47:00Z DEBUG args=['/bin/systemctl', 'list-unit-files', '--full']
2021-02-18T04:47:00Z DEBUG Process finished, return code=0
2021-02-18T04:47:00Z DEBUG stdout=UNIT FILE STATE VENDOR PRESET
proc-sys-fs-binfmt_misc.automount static enabled
-.mount generated enabled
boot-efi.mount generated enabled
dev-hugepages.mount static enabled
dev-mqueue.mount static enabled
proc-sys-fs-binfmt_misc.mount disabled enabled
snap-core18-1988.mount enabled enabled
snap-lxd-19188.mount enabled enabled
snap-snapd-11036.mount enabled enabled
sys-fs-fuse-connections.mount static enabled
sys-kernel-config.mount static enabled
sys-kernel-debug.mount static enabled
sys-kernel-tracing.mount static enabled
apport-autoreport.path enabled enabled
systemd-ask-password-console.path static enabled
systemd-ask-password-plymouth.path static enabled
systemd-ask-password-wall.path static enabled
session-5.scope transient enabled
accounts-daemon.service enabled enabled
apparmor.service enabled enabled
apport-autoreport.service static enabled
apport-forward@.service static enabled
apport.service generated enabled
apt-daily-upgrade.service static enabled
apt-daily.service static enabled
atd.service enabled enabled
autovt@.service enabled enabled
blk-availability.service enabled enabled
bolt.service static enabled
certmonger.service disabled enabled
chrony-dnssrv@.service static enabled
chrony.service enabled enabled
chronyd.service enabled enabled
cloud-config.service enabled enabled
cloud-final.service enabled enabled
cloud-init-local.service enabled enabled
cloud-init.service enabled enabled
console-getty.service disabled disabled
console-setup.service enabled enabled
container-getty@.service static enabled
cron.service enabled enabled
cryptdisks-early.service masked enabled
cryptdisks.service masked enabled
dbus-org.freedesktop.hostname1.service static enabled
dbus-org.freedesktop.locale1.service static enabled
dbus-org.freedesktop.login1.service static enabled
dbus-org.freedesktop.resolve1.service enabled enabled
dbus-org.freedesktop.timedate1.service static enabled
dbus-org.freedesktop.timesync1.service masked enabled
dbus.service static enabled
debug-shell.service disabled disabled
dm-event.service static enabled
dmesg.service enabled enabled
e2scrub@.service static enabled
e2scrub_all.service static enabled
e2scrub_fail@.service static enabled
e2scrub_reap.service enabled enabled
emergency.service static enabled
finalrd.service enabled enabled
friendly-recovery.service static enabled
fstrim.service static enabled
fwupd-offline-update.service static enabled
fwupd-refresh.service static disabled
fwupd.service static enabled
getty-static.service static enabled
getty@.service enabled enabled
grub-common.service generated enabled
grub-initrd-fallback.service enabled enabled
hwclock.service masked enabled
initrd-cleanup.service static enabled
initrd-parse-etc.service static enabled
initrd-switch-root.service static enabled
initrd-udevadm-cleanup-db.service static enabled
irqbalance.service enabled enabled
iscsi.service enabled enabled
iscsid.service disabled enabled
keyboard-setup.service enabled enabled
kmod-static-nodes.service static enabled
kmod.service static enabled
logrotate.service static enabled
lvm2-lvmpolld.service static enabled
lvm2-monitor.service enabled enabled
lvm2-pvscan@.service static enabled
lvm2.service masked enabled
lxd-agent-9p.service enabled enabled
lxd-agent.service enabled enabled
man-db.service static enabled
mdadm-grow-continue@.service static enabled
mdadm-last-resort@.service static enabled
mdcheck_continue.service static enabled
mdcheck_start.service static enabled
mdmon@.service static enabled
mdmonitor-oneshot.service static enabled
mdmonitor.service static enabled
modprobe@.service static enabled
motd-news.service static enabled
multipath-tools-boot.service masked enabled
multipath-tools.service enabled enabled
multipathd.service enabled enabled
netplan-ovs-cleanup.service enabled-runtime enabled
networkd-dispatcher.service enabled enabled
oddjobd.service enabled enabled
ondemand.service enabled enabled
open-iscsi.service enabled enabled
open-vm-tools.service enabled enabled
packagekit-offline-update.service static enabled
packagekit.service static enabled
plymouth-halt.service static enabled
plymouth-kexec.service static enabled
plymouth-log.service static enabled
plymouth-poweroff.service static enabled
plymouth-quit-wait.service static enabled
plymouth-quit.service static enabled
plymouth-read-write.service static enabled
plymouth-reboot.service static enabled
plymouth-start.service static enabled
plymouth-switch-root.service static enabled
plymouth.service static enabled
polkit.service static enabled
pollinate.service enabled enabled
procps.service static enabled
quotaon.service static enabled
rc-local.service static enabled
rc.service masked enabled
rcS.service masked enabled
rescue.service static enabled
rsync.service enabled enabled
rsyslog.service enabled enabled
screen-cleanup.service masked enabled
secureboot-db.service enabled enabled
serial-getty@.service disabled enabled
setvtrgb.service enabled enabled
snap.lxd.activate.service enabled enabled
snap.lxd.daemon.service static enabled
snapd.apparmor.service enabled enabled
snapd.autoimport.service enabled enabled
snapd.core-fixup.service enabled enabled
snapd.failure.service static enabled
snapd.recovery-chooser-trigger.service enabled enabled
snapd.seeded.service enabled enabled
snapd.service enabled enabled
snapd.snap-repair.service static enabled
snapd.system-shutdown.service enabled enabled
ssh.service enabled enabled
ssh@.service static enabled
sshd.service enabled enabled
sssd-autofs.service indirect enabled
sssd-nss.service indirect enabled
sssd-pac.service indirect enabled
sssd-pam.service indirect enabled
sssd-ssh.service indirect enabled
sssd-sudo.service indirect enabled
sssd.service disabled enabled
sudo.service masked enabled
syslog.service enabled enabled
system-update-cleanup.service static enabled
systemd-ask-password-console.service static enabled
systemd-ask-password-plymouth.service static enabled
systemd-ask-password-wall.service static enabled
systemd-backlight@.service static enabled
systemd-binfmt.service static enabled
systemd-bless-boot.service static enabled
systemd-boot-check-no-failures.service disabled enabled
systemd-boot-system-token.service static enabled
systemd-exit.service static enabled
systemd-fsck-root.service static enabled
systemd-fsck@.service static enabled
systemd-fsckd.service static enabled
systemd-halt.service static enabled
systemd-hibernate-resume@.service static enabled
systemd-hibernate.service static enabled
systemd-hostnamed.service static enabled
systemd-hwdb-update.service static enabled
systemd-hybrid-sleep.service static enabled
systemd-initctl.service static enabled
systemd-journal-flush.service static enabled
systemd-journald.service static enabled
systemd-journald@.service static enabled
systemd-kexec.service static enabled
systemd-localed.service static enabled
systemd-logind.service static enabled
systemd-machine-id-commit.service static enabled
systemd-modules-load.service static enabled
systemd-network-generator.service disabled enabled
systemd-networkd-wait-online.service enabled enabled
systemd-networkd.service enabled enabled
systemd-poweroff.service static enabled
systemd-pstore.service enabled enabled
systemd-quotacheck.service static enabled
systemd-random-seed.service static enabled
systemd-reboot.service static enabled
systemd-remount-fs.service enabled-runtime enabled
systemd-resolved.service enabled enabled
systemd-rfkill.service static enabled
systemd-suspend-then-hibernate.service static enabled
systemd-suspend.service static enabled
systemd-sysctl.service static enabled
systemd-sysusers.service static enabled
systemd-time-wait-sync.service disabled enabled
systemd-timedated.service static enabled
systemd-timesyncd.service masked enabled
systemd-tmpfiles-clean.service static enabled
systemd-tmpfiles-setup-dev.service static enabled
systemd-tmpfiles-setup.service static enabled
systemd-udev-settle.service static enabled
systemd-udev-trigger.service static enabled
systemd-udevd.service static enabled
systemd-update-utmp-runlevel.service static enabled
systemd-update-utmp.service static enabled
systemd-user-sessions.service static enabled
systemd-volatile-root.service static enabled
udev.service static enabled
ufw.service enabled enabled
unattended-upgrades.service enabled enabled
user-runtime-dir@.service static enabled
user@.service static enabled
uuidd.service indirect enabled
vgauth.service enabled enabled
vmtoolsd.service enabled enabled
x11-common.service masked enabled
xfs_scrub@.service static enabled
xfs_scrub_all.service static enabled
xfs_scrub_fail@.service static enabled
machine.slice static enabled
system-systemd\x2dcryptsetup.slice static enabled
user.slice static enabled
apport-forward.socket enabled enabled
dbus.socket static enabled
dm-event.socket enabled enabled
iscsid.socket enabled enabled
lvm2-lvmpolld.socket enabled enabled
multipathd.socket enabled enabled
snap.lxd.daemon.unix.socket enabled enabled
snapd.socket enabled enabled
ssh.socket disabled enabled
sssd-autofs.socket enabled enabled
sssd-nss.socket enabled enabled
sssd-pac.socket enabled enabled
sssd-pam-priv.socket enabled enabled
sssd-pam.socket enabled enabled
sssd-ssh.socket enabled enabled
sssd-sudo.socket enabled enabled
syslog.socket static disabled
systemd-fsckd.socket static enabled
systemd-initctl.socket static enabled
systemd-journald-audit.socket static enabled
systemd-journald-dev-log.socket static enabled
systemd-journald-varlink@.socket static enabled
systemd-journald.socket static enabled
systemd-journald@.socket static enabled
systemd-networkd.socket enabled enabled
systemd-rfkill.socket static enabled
systemd-udevd-control.socket static enabled
systemd-udevd-kernel.socket static enabled
uuidd.socket enabled enabled
basic.target static enabled
blockdev@.target static enabled
bluetooth.target static enabled
boot-complete.target static enabled
cloud-config.target static enabled
cloud-init.target static enabled
cryptsetup-pre.target static disabled
cryptsetup.target static enabled
ctrl-alt-del.target disabled enabled
default.target static enabled
emergency.target static enabled
exit.target disabled disabled
final.target static enabled
friendly-recovery.target static enabled
getty-pre.target static disabled
getty.target static enabled
graphical.target static enabled
halt.target disabled disabled
hibernate.target static enabled
hybrid-sleep.target static enabled
initrd-fs.target static enabled
initrd-root-device.target static enabled
initrd-root-fs.target static enabled
initrd-switch-root.target static enabled
initrd.target static enabled
kexec.target disabled disabled
local-fs-pre.target static disabled
local-fs.target static enabled
multi-user.target static enabled
network-online.target static enabled
network-pre.target static disabled
network.target static disabled
nss-lookup.target static disabled
nss-user-lookup.target static disabled
paths.target static enabled
poweroff.target disabled disabled
printer.target static enabled
reboot.target disabled enabled
remote-cryptsetup.target disabled enabled
remote-fs-pre.target static disabled
remote-fs.target enabled enabled
rescue-ssh.target static enabled
rescue.target static disabled
rpcbind.target static disabled
runlevel0.target disabled enabled
runlevel1.target static enabled
runlevel2.target static enabled
runlevel3.target static enabled
runlevel4.target static enabled
runlevel5.target static enabled
runlevel6.target disabled enabled
shutdown.target static enabled
sigpwr.target static enabled
sleep.target static enabled
slices.target static enabled
smartcard.target static enabled
sockets.target static enabled
sound.target static enabled
suspend-then-hibernate.target static enabled
suspend.target static enabled
swap.target static enabled
sysinit.target static enabled
system-update-pre.target static enabled
system-update.target static enabled
time-set.target static disabled
time-sync.target static disabled
timers.target static enabled
umount.target static enabled
apt-daily-upgrade.timer enabled enabled
apt-daily.timer enabled enabled
chrony-dnssrv@.timer disabled enabled
e2scrub_all.timer enabled enabled
fstrim.timer enabled enabled
fwupd-refresh.timer enabled enabled
logrotate.timer enabled enabled
man-db.timer enabled enabled
mdadm-last-resort@.timer static enabled
mdcheck_continue.timer enabled enabled
mdcheck_start.timer enabled enabled
mdmonitor-oneshot.timer enabled enabled
motd-news.timer enabled enabled
snapd.snap-repair.timer enabled enabled
systemd-tmpfiles-clean.timer static enabled
xfs_scrub_all.timer disabled enabled
339 unit files listed.
2021-02-18T04:47:00Z DEBUG stderr=
2021-02-18T04:47:00Z DEBUG Starting external process
2021-02-18T04:47:00Z DEBUG args=['/bin/systemctl', 'list-unit-files', '--full']
2021-02-18T04:47:01Z DEBUG Process finished, return code=0
2021-02-18T04:47:01Z DEBUG stdout=UNIT FILE STATE VENDOR PRESET
proc-sys-fs-binfmt_misc.automount static enabled
-.mount generated enabled
boot-efi.mount generated enabled
dev-hugepages.mount static enabled
dev-mqueue.mount static enabled
proc-sys-fs-binfmt_misc.mount disabled enabled
snap-core18-1988.mount enabled enabled
snap-lxd-19188.mount enabled enabled
snap-snapd-11036.mount enabled enabled
sys-fs-fuse-connections.mount static enabled
sys-kernel-config.mount static enabled
sys-kernel-debug.mount static enabled
sys-kernel-tracing.mount static enabled
apport-autoreport.path enabled enabled
systemd-ask-password-console.path static enabled
systemd-ask-password-plymouth.path static enabled
systemd-ask-password-wall.path static enabled
session-5.scope transient enabled
accounts-daemon.service enabled enabled
apparmor.service enabled enabled
apport-autoreport.service static enabled
apport-forward@.service static enabled
apport.service generated enabled
apt-daily-upgrade.service static enabled
apt-daily.service static enabled
atd.service enabled enabled
autovt@.service enabled enabled
blk-availability.service enabled enabled
bolt.service static enabled
certmonger.service disabled enabled
chrony-dnssrv@.service static enabled
chrony.service enabled enabled
chronyd.service enabled enabled
cloud-config.service enabled enabled
cloud-final.service enabled enabled
cloud-init-local.service enabled enabled
cloud-init.service enabled enabled
console-getty.service disabled disabled
console-setup.service enabled enabled
container-getty@.service static enabled
cron.service enabled enabled
cryptdisks-early.service masked enabled
cryptdisks.service masked enabled
dbus-org.freedesktop.hostname1.service static enabled
dbus-org.freedesktop.locale1.service static enabled
dbus-org.freedesktop.login1.service static enabled
dbus-org.freedesktop.resolve1.service enabled enabled
dbus-org.freedesktop.timedate1.service static enabled
dbus-org.freedesktop.timesync1.service masked enabled
dbus.service static enabled
debug-shell.service disabled disabled
dm-event.service static enabled
dmesg.service enabled enabled
e2scrub@.service static enabled
e2scrub_all.service static enabled
e2scrub_fail@.service static enabled
e2scrub_reap.service enabled enabled
emergency.service static enabled
finalrd.service enabled enabled
friendly-recovery.service static enabled
fstrim.service static enabled
fwupd-offline-update.service static enabled
fwupd-refresh.service static disabled
fwupd.service static enabled
getty-static.service static enabled
getty@.service enabled enabled
grub-common.service generated enabled
grub-initrd-fallback.service enabled enabled
hwclock.service masked enabled
initrd-cleanup.service static enabled
initrd-parse-etc.service static enabled
initrd-switch-root.service static enabled
initrd-udevadm-cleanup-db.service static enabled
irqbalance.service enabled enabled
iscsi.service enabled enabled
iscsid.service disabled enabled
keyboard-setup.service enabled enabled
kmod-static-nodes.service static enabled
kmod.service static enabled
logrotate.service static enabled
lvm2-lvmpolld.service static enabled
lvm2-monitor.service enabled enabled
lvm2-pvscan@.service static enabled
lvm2.service masked enabled
lxd-agent-9p.service enabled enabled
lxd-agent.service enabled enabled
man-db.service static enabled
mdadm-grow-continue@.service static enabled
mdadm-last-resort@.service static enabled
mdcheck_continue.service static enabled
mdcheck_start.service static enabled
mdmon@.service static enabled
mdmonitor-oneshot.service static enabled
mdmonitor.service static enabled
modprobe@.service static enabled
motd-news.service static enabled
multipath-tools-boot.service masked enabled
multipath-tools.service enabled enabled
multipathd.service enabled enabled
netplan-ovs-cleanup.service enabled-runtime enabled
networkd-dispatcher.service enabled enabled
oddjobd.service enabled enabled
ondemand.service enabled enabled
open-iscsi.service enabled enabled
open-vm-tools.service enabled enabled
packagekit-offline-update.service static enabled
packagekit.service static enabled
plymouth-halt.service static enabled
plymouth-kexec.service static enabled
plymouth-log.service static enabled
plymouth-poweroff.service static enabled
plymouth-quit-wait.service static enabled
plymouth-quit.service static enabled
plymouth-read-write.service static enabled
plymouth-reboot.service static enabled
plymouth-start.service static enabled
plymouth-switch-root.service static enabled
plymouth.service static enabled
polkit.service static enabled
pollinate.service enabled enabled
procps.service static enabled
quotaon.service static enabled
rc-local.service static enabled
rc.service masked enabled
rcS.service masked enabled
rescue.service static enabled
rsync.service enabled enabled
rsyslog.service enabled enabled
screen-cleanup.service masked enabled
secureboot-db.service enabled enabled
serial-getty@.service disabled enabled
setvtrgb.service enabled enabled
snap.lxd.activate.service enabled enabled
snap.lxd.daemon.service static enabled
snapd.apparmor.service enabled enabled
snapd.autoimport.service enabled enabled
snapd.core-fixup.service enabled enabled
snapd.failure.service static enabled
snapd.recovery-chooser-trigger.service enabled enabled
snapd.seeded.service enabled enabled
snapd.service enabled enabled
snapd.snap-repair.service static enabled
snapd.system-shutdown.service enabled enabled
ssh.service enabled enabled
ssh@.service static enabled
sshd.service enabled enabled
sssd-autofs.service indirect enabled
sssd-nss.service indirect enabled
sssd-pac.service indirect enabled
sssd-pam.service indirect enabled
sssd-ssh.service indirect enabled
sssd-sudo.service indirect enabled
sssd.service disabled enabled
sudo.service masked enabled
syslog.service enabled enabled
system-update-cleanup.service static enabled
systemd-ask-password-console.service static enabled
systemd-ask-password-plymouth.service static enabled
systemd-ask-password-wall.service static enabled
systemd-backlight@.service static enabled
systemd-binfmt.service static enabled
systemd-bless-boot.service static enabled
systemd-boot-check-no-failures.service disabled enabled
systemd-boot-system-token.service static enabled
systemd-exit.service static enabled
systemd-fsck-root.service static enabled
systemd-fsck@.service static enabled
systemd-fsckd.service static enabled
systemd-halt.service static enabled
systemd-hibernate-resume@.service static enabled
systemd-hibernate.service static enabled
systemd-hostnamed.service static enabled
systemd-hwdb-update.service static enabled
systemd-hybrid-sleep.service static enabled
systemd-initctl.service static enabled
systemd-journal-flush.service static enabled
systemd-journald.service static enabled
systemd-journald@.service static enabled
systemd-kexec.service static enabled
systemd-localed.service static enabled
systemd-logind.service static enabled
systemd-machine-id-commit.service static enabled
systemd-modules-load.service static enabled
systemd-network-generator.service disabled enabled
systemd-networkd-wait-online.service enabled enabled
systemd-networkd.service enabled enabled
systemd-poweroff.service static enabled
systemd-pstore.service enabled enabled
systemd-quotacheck.service static enabled
systemd-random-seed.service static enabled
systemd-reboot.service static enabled
systemd-remount-fs.service enabled-runtime enabled
systemd-resolved.service enabled enabled
systemd-rfkill.service static enabled
systemd-suspend-then-hibernate.service static enabled
systemd-suspend.service static enabled
systemd-sysctl.service static enabled
systemd-sysusers.service static enabled
systemd-time-wait-sync.service disabled enabled
systemd-timedated.service static enabled
systemd-timesyncd.service masked enabled
systemd-tmpfiles-clean.service static enabled
systemd-tmpfiles-setup-dev.service static enabled
systemd-tmpfiles-setup.service static enabled
systemd-udev-settle.service static enabled
systemd-udev-trigger.service static enabled
systemd-udevd.service static enabled
systemd-update-utmp-runlevel.service static enabled
systemd-update-utmp.service static enabled
systemd-user-sessions.service static enabled
systemd-volatile-root.service static enabled
udev.service static enabled
ufw.service enabled enabled
unattended-upgrades.service enabled enabled
user-runtime-dir@.service static enabled
user@.service static enabled
uuidd.service indirect enabled
vgauth.service enabled enabled
vmtoolsd.service enabled enabled
x11-common.service masked enabled
xfs_scrub@.service static enabled
xfs_scrub_all.service static enabled
xfs_scrub_fail@.service static enabled
machine.slice static enabled
system-systemd\x2dcryptsetup.slice static enabled
user.slice static enabled
apport-forward.socket enabled enabled
dbus.socket static enabled
dm-event.socket enabled enabled
iscsid.socket enabled enabled
lvm2-lvmpolld.socket enabled enabled
multipathd.socket enabled enabled
snap.lxd.daemon.unix.socket enabled enabled
snapd.socket enabled enabled
ssh.socket disabled enabled
sssd-autofs.socket enabled enabled
sssd-nss.socket enabled enabled
sssd-pac.socket enabled enabled
sssd-pam-priv.socket enabled enabled
sssd-pam.socket enabled enabled
sssd-ssh.socket enabled enabled
sssd-sudo.socket enabled enabled
syslog.socket static disabled
systemd-fsckd.socket static enabled
systemd-initctl.socket static enabled
systemd-journald-audit.socket static enabled
systemd-journald-dev-log.socket static enabled
systemd-journald-varlink@.socket static enabled
systemd-journald.socket static enabled
systemd-journald@.socket static enabled
systemd-networkd.socket enabled enabled
systemd-rfkill.socket static enabled
systemd-udevd-control.socket static enabled
systemd-udevd-kernel.socket static enabled
uuidd.socket enabled enabled
basic.target static enabled
blockdev@.target static enabled
bluetooth.target static enabled
boot-complete.target static enabled
cloud-config.target static enabled
cloud-init.target static enabled
cryptsetup-pre.target static disabled
cryptsetup.target static enabled
ctrl-alt-del.target disabled enabled
default.target static enabled
emergency.target static enabled
exit.target disabled disabled
final.target static enabled
friendly-recovery.target static enabled
getty-pre.target static disabled
getty.target static enabled
graphical.target static enabled
halt.target disabled disabled
hibernate.target static enabled
hybrid-sleep.target static enabled
initrd-fs.target static enabled
initrd-root-device.target static enabled
initrd-root-fs.target static enabled
initrd-switch-root.target static enabled
initrd.target static enabled
kexec.target disabled disabled
local-fs-pre.target static disabled
local-fs.target static enabled
multi-user.target static enabled
network-online.target static enabled
network-pre.target static disabled
network.target static disabled
nss-lookup.target static disabled
nss-user-lookup.target static disabled
paths.target static enabled
poweroff.target disabled disabled
printer.target static enabled
reboot.target disabled enabled
remote-cryptsetup.target disabled enabled
remote-fs-pre.target static disabled
remote-fs.target enabled enabled
rescue-ssh.target static enabled
rescue.target static disabled
rpcbind.target static disabled
runlevel0.target disabled enabled
runlevel1.target static enabled
runlevel2.target static enabled
runlevel3.target static enabled
runlevel4.target static enabled
runlevel5.target static enabled
runlevel6.target disabled enabled
shutdown.target static enabled
sigpwr.target static enabled
sleep.target static enabled
slices.target static enabled
smartcard.target static enabled
sockets.target static enabled
sound.target static enabled
suspend-then-hibernate.target static enabled
suspend.target static enabled
swap.target static enabled
sysinit.target static enabled
system-update-pre.target static enabled
system-update.target static enabled
time-set.target static disabled
time-sync.target static disabled
timers.target static enabled
umount.target static enabled
apt-daily-upgrade.timer enabled enabled
apt-daily.timer enabled enabled
chrony-dnssrv@.timer disabled enabled
e2scrub_all.timer enabled enabled
fstrim.timer enabled enabled
fwupd-refresh.timer enabled enabled
logrotate.timer enabled enabled
man-db.timer enabled enabled
mdadm-last-resort@.timer static enabled
mdcheck_continue.timer enabled enabled
mdcheck_start.timer enabled enabled
mdmonitor-oneshot.timer enabled enabled
motd-news.timer enabled enabled
snapd.snap-repair.timer enabled enabled
systemd-tmpfiles-clean.timer static enabled
xfs_scrub_all.timer disabled enabled
339 unit files listed.
2021-02-18T04:47:01Z DEBUG stderr=
2021-02-18T04:47:01Z DEBUG Starting external process
2021-02-18T04:47:01Z DEBUG args=['pam-auth-update', '--package', '--enable', 'mkhomedir']
2021-02-18T04:47:01Z DEBUG Process finished, return code=0
2021-02-18T04:47:01Z DEBUG stdout=
2021-02-18T04:47:01Z DEBUG stderr=
2021-02-18T04:47:01Z DEBUG Starting external process
2021-02-18T04:47:01Z DEBUG args=['/bin/systemctl', 'is-active', 'oddjobd.service']
2021-02-18T04:47:01Z DEBUG Process finished, return code=0
2021-02-18T04:47:01Z DEBUG stdout=active
2021-02-18T04:47:01Z DEBUG stderr=
2021-02-18T04:47:01Z DEBUG Starting external process
2021-02-18T04:47:01Z DEBUG args=['/bin/systemctl', 'is-enabled', 'oddjobd.service']
2021-02-18T04:47:01Z DEBUG Process finished, return code=0
2021-02-18T04:47:01Z DEBUG stdout=enabled
2021-02-18T04:47:01Z DEBUG stderr=
2021-02-18T04:47:01Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:47:01Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:47:01Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:47:01Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:47:01Z INFO SSSD enabled
2021-02-18T04:47:01Z DEBUG Starting external process
2021-02-18T04:47:01Z DEBUG args=['/bin/systemctl', 'restart', 'sssd.service']
2021-02-18T04:47:02Z DEBUG Process finished, return code=0
2021-02-18T04:47:02Z DEBUG stdout=
2021-02-18T04:47:02Z DEBUG stderr=
2021-02-18T04:47:02Z DEBUG Starting external process
2021-02-18T04:47:02Z DEBUG args=['/bin/systemctl', 'is-active', 'sssd.service']
2021-02-18T04:47:02Z DEBUG Process finished, return code=0
2021-02-18T04:47:02Z DEBUG stdout=active
2021-02-18T04:47:02Z DEBUG stderr=
2021-02-18T04:47:02Z DEBUG Restart of sssd.service complete
2021-02-18T04:47:02Z DEBUG Starting external process
2021-02-18T04:47:02Z DEBUG args=['/bin/systemctl', 'enable', 'sssd.service']
2021-02-18T04:47:02Z DEBUG Process finished, return code=0
2021-02-18T04:47:02Z DEBUG stdout=
2021-02-18T04:47:02Z DEBUG stderr=Synchronizing state of sssd.service with SysV service script with /lib/systemd/systemd-sysv-install.
Executing: /lib/systemd/systemd-sysv-install enable sssd
Created symlink /etc/systemd/system/multi-user.target.wants/sssd.service → /lib/systemd/system/sssd.service.
2021-02-18T04:47:02Z DEBUG Backing up system configuration file '/etc/ldap/ldap.conf'
2021-02-18T04:47:02Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
2021-02-18T04:47:02Z DEBUG Updating configuration file /etc/ldap/ldap.conf
2021-02-18T04:47:02Z DEBUG # File modified by ipa-client-install
# We do not want to break your existing configuration, hence:
# URI, BASE, TLS_CACERT and SASL_MECH
# have been added if they were not set.
# In case any of them were set, a comment has been inserted and
# "# CONF_NAME modified by IPA" added to the line above.
# To use IPA server with openLDAP tools, please comment out your
# existing configuration for these options and uncomment the
# corresponding lines generated by IPA.
#
# LDAP Defaults
#
# See ldap.conf(5) for details
# This file should be world readable but not world writable.
#BASE dc=example,dc=com
#URI ldap://ldap.example.com ldap://ldap-master.example.com:666
#SIZELIMIT 12
#TIMELIMIT 15
#DEREF never
# TLS certificates (needed for GnuTLS)
# TLS_CACERT modified by IPA
#TLS_CACERT /etc/ipa/ca.crt
TLS_CACERT /etc/ssl/certs/ca-certificates.crt
URI ldaps://ipa3.example.org
BASE dc=example,dc=org
SASL_MECH GSSAPI
2021-02-18T04:47:02Z INFO Configured /etc/openldap/ldap.conf
2021-02-18T04:47:02Z DEBUG Starting external process
2021-02-18T04:47:02Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:02Z DEBUG Process finished, return code=2
2021-02-18T04:47:02Z DEBUG stdout=
2021-02-18T04:47:02Z DEBUG stderr=
2021-02-18T04:47:03Z DEBUG Starting external process
2021-02-18T04:47:03Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:03Z DEBUG Process finished, return code=2
2021-02-18T04:47:03Z DEBUG stdout=
2021-02-18T04:47:03Z DEBUG stderr=
2021-02-18T04:47:04Z DEBUG Starting external process
2021-02-18T04:47:04Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:04Z DEBUG Process finished, return code=2
2021-02-18T04:47:04Z DEBUG stdout=
2021-02-18T04:47:04Z DEBUG stderr=
2021-02-18T04:47:05Z DEBUG Starting external process
2021-02-18T04:47:05Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:05Z DEBUG Process finished, return code=2
2021-02-18T04:47:05Z DEBUG stdout=
2021-02-18T04:47:05Z DEBUG stderr=
2021-02-18T04:47:06Z DEBUG Starting external process
2021-02-18T04:47:06Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:06Z DEBUG Process finished, return code=2
2021-02-18T04:47:06Z DEBUG stdout=
2021-02-18T04:47:06Z DEBUG stderr=
2021-02-18T04:47:07Z DEBUG Starting external process
2021-02-18T04:47:07Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:07Z DEBUG Process finished, return code=2
2021-02-18T04:47:07Z DEBUG stdout=
2021-02-18T04:47:07Z DEBUG stderr=
2021-02-18T04:47:08Z DEBUG Starting external process
2021-02-18T04:47:08Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:08Z DEBUG Process finished, return code=2
2021-02-18T04:47:08Z DEBUG stdout=
2021-02-18T04:47:08Z DEBUG stderr=
2021-02-18T04:47:09Z DEBUG Starting external process
2021-02-18T04:47:09Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:09Z DEBUG Process finished, return code=2
2021-02-18T04:47:09Z DEBUG stdout=
2021-02-18T04:47:09Z DEBUG stderr=
2021-02-18T04:47:10Z DEBUG Starting external process
2021-02-18T04:47:10Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:10Z DEBUG Process finished, return code=2
2021-02-18T04:47:10Z DEBUG stdout=
2021-02-18T04:47:10Z DEBUG stderr=
2021-02-18T04:47:11Z DEBUG Starting external process
2021-02-18T04:47:11Z DEBUG args=['/usr/bin/getent', 'passwd', 'enroll-user@example.org']
2021-02-18T04:47:11Z DEBUG Process finished, return code=2
2021-02-18T04:47:11Z DEBUG stdout=
2021-02-18T04:47:11Z DEBUG stderr=
2021-02-18T04:47:12Z ERROR Unable to find 'enroll-user' user with 'getent passwd enroll-user@example.org'!
2021-02-18T04:47:12Z ERROR Unable to reliably detect configuration. Check NSS setup manually.
2021-02-18T04:47:12Z DEBUG Backing up system configuration file '/etc/ssh/ssh_config'
2021-02-18T04:47:12Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
2021-02-18T04:47:12Z INFO Configured /etc/ssh/ssh_config
2021-02-18T04:47:12Z DEBUG Backing up system configuration file '/etc/ssh/sshd_config'
2021-02-18T04:47:12Z DEBUG Saving Index File to '/var/lib/ipa-client/sysrestore/sysrestore.index'
2021-02-18T04:47:12Z DEBUG Starting external process
2021-02-18T04:47:12Z DEBUG args=['/usr/sbin/sshd', '-t', '-f', '/dev/null', '-o', 'AuthorizedKeysCommand=/usr/bin/sss_ssh_authorizedkeys', '-o', 'AuthorizedKeysCommandUser=nobody']
2021-02-18T04:47:12Z DEBUG Process finished, return code=0
2021-02-18T04:47:12Z DEBUG stdout=
2021-02-18T04:47:12Z DEBUG stderr=
2021-02-18T04:47:12Z INFO Configured /etc/ssh/sshd_config
2021-02-18T04:47:12Z DEBUG Starting external process
2021-02-18T04:47:12Z DEBUG args=['/bin/systemctl', 'is-active', 'sshd.service']
2021-02-18T04:47:12Z DEBUG Process finished, return code=0
2021-02-18T04:47:12Z DEBUG stdout=active
2021-02-18T04:47:12Z DEBUG stderr=
2021-02-18T04:47:12Z DEBUG Starting external process
2021-02-18T04:47:12Z DEBUG args=['/bin/systemctl', 'restart', 'sshd.service']
2021-02-18T04:47:12Z DEBUG Process finished, return code=0
2021-02-18T04:47:12Z DEBUG stdout=
2021-02-18T04:47:12Z DEBUG stderr=
2021-02-18T04:47:12Z DEBUG Starting external process
2021-02-18T04:47:12Z DEBUG args=['/bin/systemctl', 'is-active', 'sshd.service']
2021-02-18T04:47:12Z DEBUG Process finished, return code=0
2021-02-18T04:47:12Z DEBUG stdout=active
2021-02-18T04:47:12Z DEBUG stderr=
2021-02-18T04:47:12Z DEBUG Restart of sshd.service complete
2021-02-18T04:47:12Z INFO Configuring example.org as NIS domain.
2021-02-18T04:47:12Z DEBUG Starting external process
2021-02-18T04:47:12Z DEBUG args=['/usr/bin/nisdomainname']
2021-02-18T04:47:12Z DEBUG Process finished, return code=1
2021-02-18T04:47:12Z DEBUG stdout=nisdomainname: Local domain name not set
2021-02-18T04:47:12Z DEBUG stderr=
2021-02-18T04:47:12Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:47:12Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:47:12Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:47:12Z DEBUG Saving StateFile to '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T04:47:12Z INFO Client configuration complete.
2021-02-18T04:47:12Z INFO The ipa-client-install command was successful
2021-02-18T05:00:13Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T05:00:13Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
2021-02-18T05:00:13Z DEBUG Loading StateFile from '/var/lib/ipa-client/sysrestore/sysrestore.state'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment